New RefluXFS Linux flaw lets attackers gain root privileges
ResearchXFS filesystemOur summary
A critical nine-year-old race condition vulnerability, tracked as CVE-2026-64600 and dubbed RefluXFS, has been discovered in the Linux kernel's XFS filesystem. This flaw enables local attackers to overwrite protected files and escalate privileges to root. The issue affects systems using an XFS filesystem with reflink enabled—common in major enterprise Linux distributions—and running kernel versions 4.11 or newer. Standard security measures like SELinux and container isolation do not prevent exploitation due to the low-level nature of the flaw. A patch was issued on July 16, and users are urged to update their kernels immediately.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.