Updated
Updated · Qualys Blog · Jul 22
Linux Vendors Ship RefluXFS Fixes for 16.4 Million Systems Exposed to Root Escalation
Updated
Updated · Qualys Blog · Jul 22

Linux Vendors Ship RefluXFS Fixes for 16.4 Million Systems Exposed to Root Escalation

3 articles · Updated · Qualys Blog · Jul 22

Summary

  • Vendor-fixed kernels are now available and being backported for CVE-2026-64600, an XFS flaw Qualys says needs immediate patching and a reboot.
  • Since kernel 4.11 in 2017, the race condition has let an ordinary local user overwrite protected files on reflink-enabled XFS volumes and reliably gain host root privileges.
  • Qualys said the exploit works under standard hardening, including SELinux Enforcing mode, leaves no kernel log output, and has no practical temporary mitigation.
  • More than 16.4 million systems could be affected, including default XFS deployments on RHEL, Oracle Linux, Amazon Linux and Fedora, while Debian, Ubuntu and SUSE are exposed if XFS was manually chosen.

Insights

A nine-year-old bug bypasses all modern defenses. What other ticking time bombs are hiding in our critical infrastructure's code?
As AI finds flaws faster than humans can patch, are we entering an era of permanent cyber insecurity?