logo

Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover

ID: b1ae012c-9368-5784-96e3-56b679565168

STIX ID: report--b1ae012c-9368-5784-96e3-56b679565168

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

A critical local privilege escalation vulnerability (CVE-2026-64600) in the Linux XFS filesystem reflink copy-on-write path allows local attackers to gain root and overwrite protected files persistently; the flaw affects over 16 million RHEL-derived systems, was patched on July 16, 2026, and was reported by Qualys Threat Research, with immediate patching and reboot recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.