RefluXFS (CVE 2026 64600) is a high severity local privilege escalation vulnerability in the Linux kernel's XFS filesystem, disclosed by Qualys Threat Research Unit on July 22, 2026 [4]. It allows an unprivileged local user to gain root access by exploiting a race condition in the XFS copy on write (CoW) path [2][4]...

Create a landscape editorial hero image for this Studio Global article: Search & fact check with cited sources for What is the "RefluXFS" Linux kernel vulnerability (CVE 2026 64600), how does it work, which syste. Article summary: RefluXFS (CVE 2026 64600) is a high severity local privilege escalation vulnerability in the Linux kernel's XFS filesystem, disclosed by Qualys Threat Research Unit on July 22, 2026 [4].. Topic tags: general web, prompt engineering, ai, workflow, code. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickba
RefluXFS (CVE-2026-64600) is a high-severity local privilege escalation vulnerability in the Linux kernel's XFS filesystem, disclosed by Qualys Threat Research Unit on July 22, 2026 . It allows an unprivileged local user to gain root access by exploiting a race condition in the XFS copy-on-write (CoW) path
.
xfs_reflink_fill_cow_hole and xfs_reflink_fill_delalloc kernel helpers xfs_find_trim_cow_extent, the data fork mapping is NOT refreshed before the next write /etc/passwd, /etc/shadow, or SSH authorized_keys — even on systems running SELinux in Enforcing mode 3c68d44a2b49 and present in every mainline and stable kernel since then mkfs.xfs in 2019, meaning most modern XFS volumes are affected Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
RefluXFS (CVE 2026 64600) is a high severity local privilege escalation vulnerability in the Linux kernel's XFS filesystem, disclosed by Qualys Threat Research Unit on July 22, 2026 [4].
RefluXFS (CVE 2026 64600) is a high severity local privilege escalation vulnerability in the Linux kernel's XFS filesystem, disclosed by Qualys Threat Research Unit on July 22, 2026 [4]. It allows an unprivileged local user to gain root access by exploiting a race condition in the XFS copy on write (CoW) path [2][4][9].
How it works The flaw is a race condition in the xfs reflink fill cow hole and xfs reflink fill delalloc kernel helpers [8].