CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

July 23, 2026

A critical Linux kernel vulnerability, tracked as CVE-2026-64600 and named RefluXFS, has been disclosed by Qualys. The flaw, present in Linux kernels since version 4.11 (2017), allows an unprivileged local user to overwrite root-owned files on an XFS filesystem, leading to persistent root access. The vulnerability affects default installations of Red Hat Enterprise Linux, CentOS Stream, Oracle Linux, Rocky Linux, AlmaLinux, CloudLinux, Fedora Server, and Amazon Linux. The exploitation requires three conditions: Linux 4.11 or later without the fix, an XFS filesystem created with reflink=1, and the target file and an attacker-writable directory on the same filesystem. Qualys demonstrated the attack by racing against /etc/passwd and setuid-root binaries, achieving root access in under ten seconds. The flaw was discovered using an AI model, Claude Mythos Preview, which identified the race condition and wrote a working exploit. The fix was merged on July 16, 2026, and vendors have begun shipping backported kernels. Red Hat has issued Important-rated kernel advisories (RHSA-2026:39179, RHSA-2026:39180, RHSA-2026:39494). No practical mitigation exists; patching and rebooting are required. No exploitation in the wild has been reported.

CVEs: CVE-2026-64600, CVE-2026-8933

Companies: Qualys, Red Hat, Anthropic, Amazon, Oracle, Rocky Linux, AlmaLinux, CloudLinux, Fedora Project, Debian, Ubuntu, SUSE

Products: Red Hat Enterprise Linux, Fedora Server, Amazon Linux, CentOS Stream, Oracle Linux, Rocky Linux, AlmaLinux, CloudLinux, Ubuntu Desktop, Debian, SUSE Linux Enterprise Server, openSUSE