Qualys disclosed CVE-2026-64600, dubbed RefluXFS, a local privilege-escalation flaw in the Linux kernel's XFS filesystem that can let an unprivileged user gain full root access. The bug is a race condition in XFS reflink direct-I/O copy-on-write handling that allows protected root-owned files to be overwritten on disk, including /etc/passwd and SUID-root binaries, with changes persisting across reboots. Qualys said the flaw was introduced in Linux 4.11 and affects mainline and stable kernels where XFS is deployed with reflink enabled.
The issue is considered broadly exposed because reflink has been the default for mkfs.xfs since 2019, and default installations of RHEL-derived distributions, Oracle Linux, Amazon Linux, and Fedora Server may be exploitable out of the box when using reflink-enabled XFS root filesystems. Qualys estimated more than 16.4 million systems could be affected, published a working proof of concept and demonstration video, and said there are no reliable temporary mitigations beyond patching and rebooting. A fix was merged into the Linux kernel tree on July 16, 2026, and distributions are now backporting the patch.

Get the actors, campaigns, and ATT&CK mapping behind it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:47998, an Important security advisory providing a kpatch-patch live kernel update for RHEL 8 to address CVE-2026-64600. The advisory covers x86_64 and ppc64le RHEL 8 and Extended Life Cycle 8.10 variants and targets kernel-4.18.0-553.53.1.el8_10.
Red Hat published RHSA-2026:46951, an Important security advisory providing a kpatch live kernel update for RHEL 10 to address CVE-2026-64600. The advisory covers multiple RHEL 10 and 10.2 x86_64 and ppc64le variants, including Extended Update Support and Extended Life Cycle offerings, for kernel-6.12.0-211.16.1.el10_2.
Red Hat published RHSA-2026:41229 on 2026-07-17, an Important kernel security advisory for RHEL 8.8 update-service variants including TUS, SAP Solutions, and Extended Life Cycle Long Life offerings. The advisory's CVE list includes CVE-2026-64600 and ships updated kernel 4.18.0-477.154.1.el8_8 packages, with a reboot required after installation.
A public proof-of-concept for CVE-2026-64600 was disclosed via the oss-security mailing list on Openwall. The disclosure provided technical exploit details after the earlier vulnerability announcement and patch activity.
Red Hat published RHSA-2026:39494 on 2026-07-14, an Important security advisory for RHEL 10 kernel packages that lists CVE-2026-64600 and provides updated packages across multiple RHEL 10 architectures and support channels. The advisory also notes a fix for an XFS reflink-related data corruption issue and requires a reboot after installation.
Red Hat published RHSA-2026:39180 on 2026-07-14, an Important security advisory updating kernel-rt packages for Red Hat Enterprise Linux 8 and fixing CVE-2026-64600 alongside other kernel flaws. The advisory covers RHEL for Real Time 8, RHEL for Real Time for NFV 8, and RHEL 8.10 Extended Life Cycle x86_64 systems, with a reboot required after installation.
Red Hat published its CVE-2026-64600 customer portal entry, rating the flaw Important (CVSS 7.8), describing affected XFS reflink-enabled RHEL systems, and listing fixes for multiple RHEL 8 and RHEL 10 kernel packages. The advisory also documented a SystemTap mitigation and noted lower practical exposure for OpenShift Container Platform 4.
Red Hat documented CVE-2026-46113, a KVM-on-x86 shadow paging use-after-free flaw in the Linux kernel, and stated it had been addressed across multiple RHEL 8, 9, and 10 product streams via listed RHSA advisories. The bugzilla entry describes the root cause as stale rmap entries caused by unexpected GFN mismatches and says the fix zaps the existing SPTE before reinstalling mappings.
The oss-sec notice says Red Hat Product Security provided a temporary mitigation for CVE-2026-64600 using SystemTap or kprobes to block XFS reflink operations until patched kernels can be deployed. This was presented alongside the coordinated public release of the RefluXFS advisory.
Qualys publicly disclosed CVE-2026-64600, dubbed RefluXFS, as a local privilege-escalation flaw in the Linux kernel's XFS filesystem that can let an unprivileged user overwrite protected root-owned files and gain root access.
A patch addressing the RefluXFS local privilege-escalation flaw was merged into the Linux kernel source tree. Both references anchor this merge to July 16, 2026.
An upstream advisory published on lore.kernel.org disclosed CVE-2026-53359, a Linux kernel KVM x86 shadow paging use-after-free caused by reuse of a shadow page with an unexpected role. Red Hat later tracked the issue in Bugzilla and listed fixes across multiple RHEL and OpenShift product streams.
Qualys said the vulnerability later tracked as CVE-2026-64600 was introduced in Linux kernel 4.11 in February 2017 in XFS reflink direct-I/O copy-on-write handling.
Red Hat reported multiple July 29, 2026 advisories addressing CVE-2026-64600 across RHEL 9 product streams, including RHEL 9, RHEL 9.6 Extended Update Support, and SAP Solutions variants. This expands vendor remediation beyond the previously captured RHEL 8 live patch and earlier July 14 advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
28 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcecyberveille.ch
Open sourcexakep.ru
Open sourceseclists.org
Open sourcecdn2.qualys.com
Open sourceseclists.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.