logo

CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation

ID: 2bbcd977-fb3c-56f7-88dd-4afa06441fd7

STIX ID: report--2bbcd977-fb3c-56f7-88dd-4afa06441fd7

Feed Name: SOC Prime Blog

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-25

Author: SOC Prime Team

...
...

CVE-2026-64600 (RefluXFS) is a Linux kernel vulnerability in the XFS reflink copy-on-write path that allows an unprivileged local attacker to exploit a race between concurrent O_DIRECT writes to overwrite readable files and achieve persistent root privilege; exploitation was demonstrated against default RHEL 10.2. The issue affects kernels 4.11+ on XFS volumes with reflink enabled, leaves minimal forensic evidence, and is best mitigated by applying vendor kernel patches and rebooting to the fixed kernel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.