[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGK61rItksSHPoxr2uM1K-ko2UH9pWUlESxlZlnh_0PQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e4d02768-07a1-4641-8c4b-2912a2bc7755","nine-year-old-linux-kernel-race-condition-grants-root-access-via-xfs-flaw","e0749ce0-d326-4588-be81-7cd4d7850a3d","Nine-Year-Old Linux Kernel Race Condition Grants Root Access via XFS Flaw","CVE-2026-64600 (RefluXFS) is a race condition vulnerability that has existed in the Linux kernel's XFS filesystem for nine years, exposing over 16.4 million systems to local privilege escalation attacks. The flaw is especially dangerous because it produces no kernel log output, making it effectively invisible to standard monitoring tools and allowing attackers to operate undetected across reboots. Race conditions like this are notoriously difficult to identify during code review, which is why they can persist undetected for nearly a decade. The breadth of affected systems — any running kernel v4.11 or later with XFS and reflink enabled — underscores the critical importance of timely patch deployment and proactive vulnerability scanning. Organizations that lack automated patch management or asset inventory processes are particularly exposed to long-lived, low-visibility vulnerabilities of this nature.","**Immediate Actions:**\n- Apply the latest Linux kernel patches addressing CVE-2026-64600 across all affected systems as an emergency priority.\n- Audit your environment to identify all systems running kernel v4.11+ with XFS filesystems and reflink enabled.\n- Consider temporarily disabling reflink on XFS volumes where patching cannot be immediately applied as a risk-reduction measure.\n\n**Detection Measures:**\n- Deploy kernel-level integrity monitoring tools (e.g., auditd, eBPF-based solutions) capable of detecting privilege escalation attempts that bypass standard kernel logging.\n- Implement file integrity monitoring (FIM) on critical protected files to catch unauthorized overwrites that exploit this race condition.\n- Correlate endpoint telemetry with SIEM rules to flag unexpected local privilege escalation events, even in the absence of kernel log output.\n\n**Long-Term Improvements:**\n- Establish an automated patch management pipeline that enforces SLAs for critical kernel CVEs across your entire Linux fleet.\n- Maintain a current and accurate software\u002Fasset inventory to rapidly determine blast radius when new vulnerabilities are disclosed.\n- Conduct regular vulnerability assessments and subscribe to kernel security advisories (e.g., kernel.org, distro security mailing lists) to reduce mean time to detection for future flaws.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","CIS Control 8: Audit Log Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 CM-6: Configuration Settings","NIST CSF ID.VM-1: Vulnerabilities are identified and documented","NIST CSF RS.DE-1: Anomalies and events are detected","ITIL Change Management: Emergency Change procedures for critical patches","ISO\u002FIEC 27001 Annex A 12.6.1: Management of Technical Vulnerabilities","published","2026-07-23T12:20:21.803535+00:00","2026-07-23T12:20:21.528+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Flinux\u002Fnew-refluxfs-linux-flaw-lets-attackers-gain-root-privileges\u002F","new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges-20c1de","New RefluXFS Linux flaw lets attackers gain root privileges",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"26dab1a7-35a3-463a-ad2c-2ab93828ed96","2026-07-23","afternoon","ThreatNoir Afternoon Brief — July 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-23\u002Fthreatnoir-afternoon-brief-2026-07-23.mp3"]