CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation
ID: 2bbcd977-fb3c-56f7-88dd-4afa06441fd7
STIX ID: report--2bbcd977-fb3c-56f7-88dd-4afa06441fd7
Feed Name: SOC Prime Blog
CVE-2026-64600 (RefluXFS) is a Linux kernel vulnerability in the XFS reflink copy-on-write path that allows an unprivileged local attacker to exploit a race between concurrent O_DIRECT writes to overwrite readable files and achieve persistent root privilege; exploitation was demonstrated against default RHEL 10.2. The issue affects kernels 4.11+ on XFS volumes with reflink enabled, leaves minimal forensic evidence, and is best mitigated by applying vendor kernel patches and rebooting to the fixed kernel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
