XFS reflink race lets unprivileged users seize root on default Linux installs

Qualys disclosed CVE-2026-64600, a race in XFS reflink that lets an unprivileged local user overwrite root-owned files and gain persistent root on default installations of RHEL, Fedora Server, Amazon Linux and other reflink-enabled XFS systems. The exploit requires Linux 4.11+ with reflink=1 and an attacker-writable directory on the same XFS volume as a protected file; it operates at the block layer and can survive reboots. Vendors have issued backported kernel fixes and recommend updating and rebooting; there are no practical mitigations otherwise. Check your XFS configurations (reflink status) and apply the appropriate RHSA advisories for your distro to verify patched kernels are running.
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs The Hacker News
- RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) Qualys
- Linux XFS has a decade-old race condition allowing full root access Network World
- Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover Tech Times
- Linux kernel flaw lets local users gain root access SecurityBrief Australia
Reading Insights
0
10
5 min
vs 6 min read
91%
1,170 → 103 words
Want the full story? Read the original article
Read on The Hacker News