CVE-2026-64600
Microsoft patch: CBL-Mariner Releases.
Vulnerabilities · 54 days ago
An ordinary local account can turn into root on affected XFS hosts even when SELinux is Enforcing. The break is in the filesystem layer, so host hardening does not contain it once a local user can touch the race.
Qualys published a proof of concept for CVE-2026-64600 and says the exploit is reliable, leaves no kernel log output, and works on XFS root filesystems with reflink enabled. It affects Linux systems including default installs of RHEL, Oracle Linux, Amazon Linux, and Fedora, and the on-disk change survives reboot.
That means a local compromise is no longer scoped to one user account. On exposed or multi-tenant Linux servers, the attacker can overwrite protected files and keep the result across restarts.
Microsoft patch: CBL-Mariner Releases.
3 sources covering this story
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot
RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) | Qualys
Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path.
Part of the PlainSec briefing for 2026-07-22