A public proof-of-concept exploit has been released for CVE-2026-64600, a local privilege escalation flaw in the Linux kernel's XFS reflink handling known as RefluXFS. The exploit code uses the FICLONE ioctl to clone /etc/passwd into a writable file on the same XFS device, then races concurrent O_DIRECT writes across 32 threads to corrupt the original file and alter the root account entry, demonstrating a path from local access to elevated privileges on raw local XFS filesystems.
Follow-up discussion on the oss-sec mailing list said the PoC succeeds immediately on a local XFS system but has been difficult to reproduce when XFS is exported over NFS or placed beneath layered filesystems. Red Hat's Marco Benatto and XFS maintainer Darrick J. Wong said exploitation may still be possible if reflink semantics are preserved, but added RPC and filesystem-stack overhead appear to change or narrow the race window. Even where NFS reduces the likelihood of directly overwriting files such as /etc/passwd, the flaw could still let one user manipulate another user's files on affected systems.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Marco Benatto said he had not tested exploitation over NFS or layered filesystems but believed the exploit would likely remain valid if reflink semantics were preserved, though added overhead could make the race harder. Darrick J. Wong added that exploitation was still likely possible under direct-I/O conditions, but extra RPC work in NFS probably makes the race much harder to reproduce.
In oss-sec discussion, Dr. Thomas Orgis reported that the public proof-of-concept succeeded instantly on a local XFS system but ran unsuccessfully for several minutes when the XFS filesystem was exported over NFS. He said this appeared to reduce the impact from full system compromise to one user manipulating another user's files in his NFS scenario.
A public GitHub repository, CVE-2026-64600-Refluxfs-PoC, was uploaded by litosmartin with exploit code in refluxfs.c. The PoC targets local privilege escalation on XFS by cloning /etc/passwd and racing direct writes against reflinked data.
A Qualys Security Advisory about CVE-2026-64600 was posted to oss-security. Later references identify this July 22 advisory as the basis for subsequent discussion and the public proof-of-concept.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.