
XFS reflink race lets unprivileged users seize root on default Linux installs
Qualys disclosed CVE-2026-64600, a race in XFS reflink that lets an unprivileged local user overwrite root-owned files and gain persistent root on default installations of RHEL, Fedora Server, Amazon Linux and other reflink-enabled XFS systems. The exploit requires Linux 4.11+ with reflink=1 and an attacker-writable directory on the same XFS volume as a protected file; it operates at the block layer and can survive reboots. Vendors have issued backported kernel fixes and recommend updating and rebooting; there are no practical mitigations otherwise. Check your XFS configurations (reflink status) and apply the appropriate RHSA advisories for your distro to verify patched kernels are running.
