RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
ID: 240cea0e-3926-5c7b-97a8-2ea71e3bd20e
STIX ID: report--240cea0e-3926-5c7b-97a8-2ea71e3bd20e
Feed Name: cybersecurityNews.com
Qualys TRU disclosed RefluXFS (CVE-2026-64600), a race condition in the XFS reflink copy-on-write path that allows unprivileged local users to perform concurrent O_DIRECT writes to corrupt on-disk blocks and silently escalate to root, bypassing SELinux and container isolation; the bug affects Linux kernels since 4.11 on reflink-enabled XFS volumes, impacts millions of systems, leaves no kernel log artifacts, and requires immediate patching and reboot as there is currently no reliable workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
