RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)
8 relevance
Score Breakdown
technical depth 9
novelty 8
actionability 8
community 7
strategic 7
personal 7
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Linux kernel privilege escalation in XFS, actionable for security patching.
Summary
Qualys and Anthropic used Claude Mythos Preview to discover CVE-2026-64600, a race condition in the Linux kernel's XFS copy-on-write path present since kernel 4.11. The flaw allows any local unprivileged user to overwrite protected files at the block layer, reliably gaining root even under SELinux Enforcing, with no kernel log output. Over 16.4 million systems (RHEL, Amazon Linux, Fedora) with XFS reflink enabled are affected; vendor-fixed kernels are available and require immediate patching.
Author
Saeed Abbasi — Head of Threat Research Unit (TRU), Director of Product...