Bleepingcomputer
Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local users to gain root access by exploiting a race condition in the copy-on-write path. This flaw affects over 16 million systems using Red Hat Enterprise Linux and its derivatives, including Oracle Linux and Amazon Linux, all of which have reflink enabled by default. The vulnerability enables attackers to overwrite protected files without detection, as the modifications persist across reboots and leave no kernel log output. The flaw has existed since kernel version 4.11, released in 2017, and was patched on July 16, 2026, just days before its public disclosure. Qualys Threat Research Unit discovered the flaw and reported it on July 22, 2026. Immediate action is required to apply the patch and reboot affected systems to mitigate the risk.
Key Points: • CVE-2026-64600 allows local users to gain root access on affected Linux systems. • The vulnerability affects over 16 million systems with XFS filesystem and reflink enabled. • A patch was released on July 16, 2026, but immediate remediation is necessary.