RefluXFS — CVE-2026-64600
Purpose / CSI Use Case
Linux/XFS local privilege-escalation vulnerability watch and emergency patching reference for servers, multi-tenant hosts, CI runners and systems where untrusted local code can execute.
Source Notes
Verified as CVE-2026-64600. RefluXFS affects vulnerable Linux kernels using XFS with reflink enabled and can allow an unprivileged local user to overwrite root-owned file data while preserving file metadata characteristics, enabling persistent privilege escalation. The issue traces to Linux 4.11-era code; the fix was merged in July 2026 and vendors have begun shipping backports. Exposure requires an unpatched kernel, XFS created with reflink=1, and attacker-writable and readable target locations on the same XFS filesystem. RHEL-family systems, Fedora Server and Amazon Linux are important exposure candidates because XFS/reflink configurations can be common; Ubuntu/Debian are not generally XFS-root by default but can be exposed when XFS reflink was selected. CSI action: inventory XFS filesystems, check reflink feature and exact kernel/vendor advisory status, prioritize Internet-facing/multi-user/CI/container hosts where local code can execute, patch/reboot into the fixed kernel, then verify running kernel. Do not assume a sysctl or mount-option workaround; published reporting states no practical post-creation reflink disable mitigation. Sources: NVD CVE-2026-64600 and The Hacker News report dated 2026-07-23.
Official / Repository URL
https://nvd.nist.gov/vuln/detail/CVE-2026-64600
Legacy Metadata
- Added: August 8, 2026
- Category: Cybersecurity
- License: Security advisory / CVE reference
- Priority: EXTREMELY HIGH
Migration Notes
Imported deterministically from the canonical CSI Resource Hub Notion export.
No testing, deployment, approval, or production status has been inferred during migration.
Cyber Space Infocom
Making Technology Work for You