Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel XFS reflink local root flaw (CVE-2026-64600)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-64600 in the Linux kernel XFS reflink path lets a local attacker overwrite root-owned files and gain persistent root access on affected hosts. The flaw affects reflink-enabled XFS installs, including default deployments on some Red Hat Enterprise Linux, Fedora Server, and Amazon Linux systems. Vendors have started shipping backported fixes, so exposed systems need patching and rebooting.

Related Happenings

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
H score37 First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

CISA expands KEV catalog and sets February 16 remediation deadline

Public Sector Action
H score34 First: 27.01.2026 12:37 Last: 27.01.2026 12:37 Sources 1

About this happening: CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...

Timeline

  1. 23.07.2026 11:04 2 articles · 2h ago

    Qualys discloses RefluXFS after Claude Mythos Preview finds the race

    Initial Disclosure

    Qualys disclosed RefluXFS, CVE-2026-64600, after using Claude Mythos Preview, Anthropic's restricted-access frontier model, to search the Linux kernel for a Dirty COW-like flaw; the model found a race that lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

    Show sources