RefluXFS: Linux Kernel XFS Local Privilege Escalation (CVE‑2026‑64600) Enables Root from Unprivileged Accounts
What It Is — Qualys’s Threat Research Unit disclosed CVE‑2026‑64600, a race‑condition in the XFS copy‑on‑write path of the Linux kernel. An attacker with a normal, unprivileged local account can exploit the flaw to overwrite any readable file on an XFS volume and obtain full host‑root privileges.
Exploitability — Public proof‑of‑concept exists; exploitation is highly reliable, leaves no kernel log output, and works even with SELinux in Enforcing mode. CVSS v3.1 = 9.8 (Critical).
Affected Products — Linux distributions that ship an XFS root filesystem with reflink enabled, including default installations of RHEL, Oracle Linux, Amazon Linux, Fedora, and any custom kernel version ≥ 4.11 (released 2017).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls (CC6.1) – A low‑privilege account that can become root directly breaches the Principle of Least Privilege and the “Logical Access” criteria auditors examine.
- Continuous Control Monitoring – Demonstrates the need for automated, real‑time patch‑status evidence to prove timely remediation of critical OS vulnerabilities.
- Audit Trail Integrity – Because the exploit leaves no kernel logs, organizations must rely on external compliance tooling to capture patch‑application events as verifiable audit artifacts.
Recommended Actions
- Deploy the vendor‑provided kernel patches for all affected distributions without delay.
- Reboot each host to activate the patched kernel and verify the running version via automated inventory.
- Integrate patch‑status checks into your SOC 2 continuous‑compliance platform to capture immutable evidence of remediation.
Source: Qualys Blog – RefluXFS Vulnerability (CVE‑2026‑64600)