Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel XFS reflink local root flaw (CVE-2026-64600)

Vulnerability
First reported
Last updated
Happening score
H score 83
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-64600 is a Linux kernel XFS reflink race condition, dubbed RefluXFS by Qualys TRU, that can let an unprivileged local user overwrite root-owned files and gain persistent root access. The flaw affects XFS with reflink enabled on Linux kernel v4.11 or later, including major enterprise Linux deployments, and Qualys says exploitation is highly reliable, leaves no kernel log output, and can survive a reboot. The issue was introduced in February 2017, patched upstream on July 16, and vendors have started shipping backported fixes. Red Hat, Debian, and other Linux vendors have listed affected package streams, while Qualys estimates the exposure could exceed 16.4 million systems based on its asset analysis.

Related Happenings

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
H score37 First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

CISA expands KEV catalog and sets February 16 remediation deadline

Public Sector Action
H score34 First: 27.01.2026 12:37 Last: 27.01.2026 12:37 Sources 1

About this happening: CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...

Timeline

  1. 23.07.2026 11:04 3 articles · 13d ago

    Qualys discloses RefluXFS after Claude Mythos Preview finds the race

    Initial Disclosure

    Qualys disclosed RefluXFS, CVE-2026-64600, after using Claude Mythos Preview, Anthropic's restricted-access frontier model, to search the Linux kernel for a Dirty COW-like flaw; the model found a race that lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

    Show sources