Linux Vendors Ship RefluXFS Fixes for 16.4 Million Systems Exposed to Root Escalation
Updated
Updated · Qualys Blog · Jul 22
Linux Vendors Ship RefluXFS Fixes for 16.4 Million Systems Exposed to Root Escalation
3 articles · Updated · Qualys Blog · Jul 22
Summary
Vendor-fixed kernels are now available and being backported for CVE-2026-64600, an XFS flaw Qualys says needs immediate patching and a reboot.
Since kernel 4.11 in 2017, the race condition has let an ordinary local user overwrite protected files on reflink-enabled XFS volumes and reliably gain host root privileges.
Qualys said the exploit works under standard hardening, including SELinux Enforcing mode, leaves no kernel log output, and has no practical temporary mitigation.
More than 16.4 million systems could be affected, including default XFS deployments on RHEL, Oracle Linux, Amazon Linux and Fedora, while Debian, Ubuntu and SUSE are exposed if XFS was manually chosen.