Linux kernel XFS reflink local root flaw (CVE-2026-64600)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-64600 is a Linux kernel XFS reflink race condition, dubbed RefluXFS by Qualys TRU, that can let an unprivileged local user overwrite root-owned files and gain persistent root access. The flaw affects XFS with reflink enabled on Linux kernel v4.11 or later, including major enterprise Linux deployments, and Qualys says exploitation is highly reliable, leaves no kernel log output, and can survive a reboot. The issue was introduced in February 2017, patched upstream on July 16, and vendors have started shipping backported fixes. Red Hat, Debian, and other Linux vendors have listed affected package streams, while Qualys estimates the exposure could exceed 16.4 million systems based on its asset analysis.
Related Happenings
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
Vulnerability
H score30
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
VulnerabilityAbout this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
CISA expands KEV catalog and sets February 16 remediation deadline
Public Sector Action
H score34
First: 27.01.2026 12:37
Last: 27.01.2026 12:37
Sources 1
About this happening:
CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...
CISA expands KEV catalog and sets February 16 remediation deadline
Public Sector ActionAbout this happening: CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...
Timeline
-
23.07.2026 11:04 1 articles · 13d ago
Red Hat bug tracker auto-imports XFS reflink corruption issue
Technical Analysis UpdateRed Hat's bug tracker auto-imported a kernel issue titled "kernel: XFS data corruption using reflink" and initially described possible data corruption from reflinking a file.
Show sources
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04
-
23.07.2026 11:04 1 articles · 13d ago
Red Hat begins landing kernel advisories for the RefluXFS fix
Mitigation Patch UpdateRed Hat began landing Important-rated kernel advisories for affected RHEL 8 and RHEL 10 streams, starting the patch rollout for systems exposed to the XFS reflink flaw.
Show sources
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04
-
23.07.2026 11:04 1 articles · 13d ago
Linux fix merges and vendors start shipping backported kernels
Mitigation Patch UpdateThe RefluXFS fix was merged into Linux, and vendors began shipping backported kernels that include the patch.
Show sources
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04
-
23.07.2026 11:04 3 articles · 13d ago
Qualys discloses RefluXFS after Claude Mythos Preview finds the race
Initial DisclosureQualys disclosed RefluXFS, CVE-2026-64600, after using Claude Mythos Preview, Anthropic's restricted-access frontier model, to search the Linux kernel for a Dirty COW-like flaw; the model found a race that lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.
Show sources
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04
- New RefluXFS Linux flaw lets attackers gain root privileges — www.bleepingcomputer.com — 23.07.2026 14:40
-
23.07.2026 11:04 1 articles · 13d ago
Debian tracker lists RefluXFS fixes for trixie-security and unstable
Campaign Scope UpdateDebian's tracker listed the RefluXFS fix in trixie-security as kernel 6.12.96-1 and in unstable as 7.1.4-1, showing downstream package coverage for the flaw.
Show sources
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs — thehackernews.com — 23.07.2026 11:04