Back to advisories

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root, bypassing SELinux. The flaw affects kernel versions 4.11 and later, potentially impacting over 16 million systems. Any user with local access can exploit this to gain full system compromise.

CRITICALAdvisoryJul 23, 2026
Action required
Identify all Linux systems running XFS filesystems with kernel version 4.11 or later. Prioritize patching to the latest kernel version and monitor for local privilege escalation attempts targeting XFS copy-on-write paths.
Affected products
Linux kernelSELinuxQualysClaude Mythos PreviewRHEL