An ordinary local account can turn into root on affected XFS hosts even when SELinux is Enforcing. The break is in the filesystem layer, so host hardening does not contain it once a local user can touch the race.
Qualys published a proof of concept for CVE-2026-64600 and says the exploit is reliable, leaves no kernel log output, and works on XFS root filesystems with reflink enabled. It affects Linux systems including default installs of RHEL, Oracle Linux, Amazon Linux, and Fedora, and the on-disk change survives reboot.
That means a local compromise is no longer scoped to one user account. On exposed or multi-tenant Linux servers, the attacker can overwrite protected files and keep the result across restarts.