A local privilege escalation vulnerability tracked as CVE-2026-64600, dubbed RefluXFS, was publicly disclosed on 22 July 2026 by Qualys Security Advisory. The flaw resides in the Linux kernel's XFS filesystem implementation and exploits a race condition in the reflink copy-on-write path to allow an unprivileged local user to overwrite root-owned files and attain persistent root access.
The vulnerability is classified as very critical and affects Linux kernel versions up to 6.12.95, 6.18.38, 7.1.3, and 7.2-rc3. Default installations of Red Hat Enterprise Linux (RHEL) and its derivatives, Fedora Server, and Amazon Linux are confirmed to meet the conditions required for successful exploitation. At the time of disclosure, no public exploit code had been observed, though Qualys demonstrated the attack path in their advisory.
A SystemTap-based interim mitigation was proposed by the community within hours of disclosure, blocking the vulnerable xfs_file_remap_range code path. Organisations running XFS-based Linux systems — particularly in enterprise and cloud environments — should treat this as high priority for patching and workaround deployment.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.