Linux Kernel Privilege Escalation Vulnerability “RefluXFS”
A nine-year-old vulnerability in the Linux kernel's XFS filesystem was named “RefluXFS” and tracked as CVE-2026-64600. Vulnerability has been disclosed in the Linux kernel’s XFS filesystem. The vulnerability is caused by a race condition in the XFS copy-on-write handling of reflinked files. Attackers with access to local user account can exploit this vulnerability to modify data directly on disk, survive system reboots, and leave no kernel log output. Successful exploitation can overwrite protected files and obtain root privileges.
Security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later. The list of impacted Linux distros includes Red Hat Enterprise Linux (RHEL), Oracle Linux, Amazon Linux and Fedora, as well as CentOS Stream, Rocky Linux, AlmaLinux and CloudLinux.
System owners are strongly advised to review affected systems and apply the latest kernel security updates from their respective Linux distribution vendors to reduce potential risks.
Source: bleepingcomputer.com
24 July 2026