HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

RefluXFS Linux Kernel XFS Race Condition (CVE‑2026‑64600) Grants Root from Unprivileged Accounts

Qualys discovered CVE‑2026‑64600, a race condition in the XFS filesystem that lets an unprivileged local user overwrite any file and obtain root privileges on affected Linux distributions. The flaw affects over 16 million systems and bypasses SELinux, making prompt kernel patching essential for compliance and audit readiness.

LiveThreat™ Intelligence · 📅 July 23, 2026· 📰 blog.qualys.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
blog.qualys.com

RefluXFS: Linux Kernel XFS Local Privilege Escalation (CVE‑2026‑64600) Enables Root from Unprivileged Accounts

What It Is — Qualys’s Threat Research Unit disclosed CVE‑2026‑64600, a race‑condition in the XFS copy‑on‑write path of the Linux kernel. An attacker with a normal, unprivileged local account can exploit the flaw to overwrite any readable file on an XFS volume and obtain full host‑root privileges.

Exploitability — Public proof‑of‑concept exists; exploitation is highly reliable, leaves no kernel log output, and works even with SELinux in Enforcing mode. CVSS v3.1 = 9.8 (Critical).

Affected Products — Linux distributions that ship an XFS root filesystem with reflink enabled, including default installations of RHEL, Oracle Linux, Amazon Linux, Fedora, and any custom kernel version ≥ 4.11 (released 2017).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls (CC6.1) – A low‑privilege account that can become root directly breaches the Principle of Least Privilege and the “Logical Access” criteria auditors examine.
  • Continuous Control Monitoring – Demonstrates the need for automated, real‑time patch‑status evidence to prove timely remediation of critical OS vulnerabilities.
  • Audit Trail Integrity – Because the exploit leaves no kernel logs, organizations must rely on external compliance tooling to capture patch‑application events as verifiable audit artifacts.

Recommended Actions

  • Deploy the vendor‑provided kernel patches for all affected distributions without delay.
  • Reboot each host to activate the patched kernel and verify the running version via automated inventory.
  • Integrate patch‑status checks into your SOC 2 continuous‑compliance platform to capture immutable evidence of remediation.

Source: Qualys Blog – RefluXFS Vulnerability (CVE‑2026‑64600)

📰 Original Source
https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →