logo

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) 

ID: 2a3d26c8-bf60-5a81-83e6-40480c12f095

STIX ID: report--2a3d26c8-bf60-5a81-83e6-40480c12f095

Feed Name: Qualys Blog

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Saeed Abbasi

...
...

Qualys TRU discloses RefluXFS (CVE-2026-64600), a reliable local privilege-escalation race condition in the XFS reflink copy-on-write path that lets an unprivileged user overwrite any readable file on reflink-enabled XFS volumes and achieve host root; the issue affects kernels since v4.11 on reflink-enabled XFS filesystems across many enterprise distributions, persists across reboot, leaves no kernel logs, and is mitigated only by applying vendor patches and rebooting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.