Bleepingcomputer
Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover
Article Content
A critical vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local users to gain root access by exploiting a race condition in the copy-on-write path. This flaw affects over 16 million systems using Red Hat Enterprise Linux and its derivatives, including Oracle Linux and Amazon Linux, all of which have reflink enabled by default. The vulnerability enables attackers to overwrite protected files without detection, as the modifications persist across reboots and leave no kernel log output. The flaw has existed since kernel version 4.11, released in 2017, and was patched on July 16, 2026, just days before its public disclosure. Qualys Threat Research Unit discovered the flaw and reported it on July 22, 2026. Immediate action is required to apply the patch and reboot affected systems to mitigate the risk.
Key Points: • CVE-2026-64600 allows local users to gain root access on affected Linux systems. • The vulnerability affects over 16 million systems with XFS filesystem and reflink enabled. • A patch was released on July 16, 2026, but immediate remediation is necessary.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.