Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover

Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover

First seen 23 Jul 2026, 14:24 UTC CybersecuritynewsBleepingcomputerTechtimesFeeds.4SysopsCsoonline+2 86% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local users to gain root access by exploiting a race condition in the copy-on-write path. This flaw affects over 16 million systems using Red Hat Enterprise Linux and its derivatives, including Oracle Linux and Amazon Linux, all of which have reflink enabled by default. The vulnerability enables attackers to overwrite protected files without detection, as the modifications persist across reboots and leave no kernel log output. The flaw has existed since kernel version 4.11, released in 2017, and was patched on July 16, 2026, just days before its public disclosure. Qualys Threat Research Unit discovered the flaw and reported it on July 22, 2026. Immediate action is required to apply the patch and reboot affected systems to mitigate the risk.

Key Points: • CVE-2026-64600 allows local users to gain root access on affected Linux systems. • The vulnerability affects over 16 million systems with XFS filesystem and reflink enabled. • A patch was released on July 16, 2026, but immediate remediation is necessary.

ThreatCluster AI

Timeline

2016-10-21
Public exploit for CVE-2016-5195 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-05-30
CVE-2026-46242 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-16
Patch for RefluXFS vulnerability merged
A patch addressing CVE-2026-64600 was merged into the Linux kernel source tree, prior to public disclosure.
Techtimes
2026-07-22
RefluXFS vulnerability disclosed
Qualys Threat Research Unit disclosed the RefluXFS vulnerability, highlighting its potential impact on millions of systems.
Bleepingcomputer
2026-07-23
CVE-2026-64600 published
The vulnerability was officially published, confirming its critical nature and the need for immediate patching.
Cybersecuritynews

Community

Browse all →