← All briefs
Brief·6 sources23 Jul 2026

CVE-2026-64600 RefluXFS Flaw Enables Root On RHEL Linux Installs

vulnerability-disclosureprivilege-escalationzero-day-exploitpatch-managementcloud-security

Summary

A local privilege escalation vulnerability tracked as CVE-2026-64600, dubbed RefluXFS, was publicly disclosed on 22 July 2026 by Qualys Security Advisory. The flaw resides in the Linux kernel's XFS filesystem implementation and exploits a race condition in the reflink copy-on-write path to allow an unprivileged local user to overwrite root-owned files and attain persistent root access.

The vulnerability is classified as very critical and affects Linux kernel versions up to 6.12.95, 6.18.38, 7.1.3, and 7.2-rc3. Default installations of Red Hat Enterprise Linux (RHEL) and its derivatives, Fedora Server, and Amazon Linux are confirmed to meet the conditions required for successful exploitation. At the time of disclosure, no public exploit code had been observed, though Qualys demonstrated the attack path in their advisory.

A SystemTap-based interim mitigation was proposed by the community within hours of disclosure, blocking the vulnerable xfs_file_remap_range code path. Organisations running XFS-based Linux systems — particularly in enterprise and cloud environments — should treat this as high priority for patching and workaround deployment.

Timeline

  1. 23 July 2026
    The Hacker News and VulDB publish coverage of CVE-2026-64600
    Mainstream security outlets reported on the vulnerability, confirming its classification as very critical and highlighting the exposure of default RHEL, Fedora Server, and Amazon Linux installations.
  2. 22 July 2026
    Qualys publishes RefluXFS advisory for CVE-2026-64600 on oss-security
    Qualys Security Advisory publicly disclosed the local privilege escalation vulnerability in the Linux kernel XFS reflink path, providing full technical analysis and exploitation details on the oss-security mailing list.
  3. 22 July 2026
    SystemTap interim mitigation proposed by community researcher
    Marco Benatto posted a SystemTap script to oss-security capable of blocking the vulnerable xfs_file_remap_range code path as a temporary workaround whilst kernel patches are developed.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.

CVE-2026-64600 RefluXFS Flaw Enables Root On RHEL Linux Installs — Deltabridge