CVE Tools

Новая уязвимость RefluXFS позволяет получить root-права в Linux

Хакер (xakep.ru)By Мария Нефёдова

PatchLinux kernel XFS

Our summary

Researchers at Qualys have discovered a nine-year-old flaw in the XFS file system, identified as CVE-2026-64600 and named RefluXFS. This vulnerability allows unprivileged local users to overwrite protected files and gain root privileges by exploiting a race condition during reflink operations. The bug was introduced in Linux 4.11 (released in 2017) and has been present in all subsequent stable kernel versions. Systems using XFS with reflink enabled—common in distributions like Red Hat, CentOS, Oracle Linux, and others—are potentially affected. Researchers estimate over 16.4 million systems could be impacted. A fix was committed on July 16, 2026, and distribution vendors are now rolling out patches. Administrators are urged to update their kernels promptly, especially on public-facing or multi-user systems.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store