Linux kernel flaw lets local users gain root access

Qualys has identified a critical Linux kernel vulnerability, CVE-2026-64600, affecting XFS filesystems that allows local users to gain root access. The flaw, which has existed since kernel 4.11, enables attackers to overwrite protected files and bypass security measures like SELinux.
Why it matters
This vulnerability poses a significant security risk to millions of shared servers and multi-tenant environments, potentially allowing attackers to establish persistent root-level control.
Qualys has disclosed a Linux kernel vulnerability called RefluXFS that could allow a local user to gain root privileges on affected systems. The flaw may affect more than 16.4 million systems worldwide.
Tracked as CVE-2026-64600, the vulnerability lies in the XFS filesystem copy-on-write path and has been present since Linux kernel 4.11. It affects XFS-based environments across distributions including Red Hat Enterprise Linux, Oracle Linux, Amazon Linux and Fedora. Debian, Ubuntu and SUSE can also be exposed if administrators choose XFS with reflink enabled.
Qualys said the flaw lets an ordinary local account overwrite protected files on disk and then obtain root privileges on the host. The issue can be exploited even on systems running SELinux in enforcing mode, leaves no kernel log output and survives a reboot.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in