Critical RefluXFS Vulnerability Exposes Millions of Linux Systems to Root Takeover

Critical RefluXFS Vulnerability Exposes Millions of Linux Systems to Root Takeover

First seen 23 Jul 2026, 14:24 UTC CybersecuritynewsBleepingcomputerTechtimesFeeds.4Sysopsblog.qualys.com+1 86% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical flaw in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local users to gain root access on systems running Red Hat Enterprise Linux and its derivatives. The vulnerability, discovered by Qualys Threat Research Unit, affects over 16 million systems worldwide. It exploits a race condition during concurrent direct I/O operations, enabling attackers to overwrite protected files without detection. The flaw has existed since kernel version 4.11, released in 2017, and was patched on July 16, 2026. Affected distributions include RHEL, Oracle Linux, and Fedora. Standard security measures like SELinux and container isolation do not mitigate this vulnerability. Immediate action is required to apply the patch and reboot systems to prevent exploitation.

Key Points: • CVE-2026-64600 allows local users to gain root access on affected Linux systems. • The vulnerability affects over 16 million systems running XFS with reflink enabled. • Standard security defenses are ineffective against this flaw, necessitating urgent patching.

ThreatCluster AI

Timeline

2016-10-21
Public exploit for CVE-2016-5195 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-05-30
CVE-2026-46242 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-16
Patch for RefluXFS vulnerability merged
A patch addressing CVE-2026-64600 was merged into the Linux kernel source tree.
Techtimes
2026-07-22
RefluXFS vulnerability disclosed
Qualys disclosed the RefluXFS vulnerability, affecting millions of Linux systems.
Bleepingcomputer
2026-07-23
CVE-2026-64600 published
CVE-2026-64600 was officially published, detailing the critical XFS filesystem flaw.
Cybersecuritynews

Community

Browse all →