RefluXFS: Critical XFS Race Condition Allows Root
🛡️ A nine-year-old race condition in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600 and dubbed RefluXFS by Qualys TRU, enables local attackers to overwrite protected files and gain root privileges. The flaw affects systems with reflink-enabled XFS on kernel v4.11+ and requires a directory writable by an unprivileged user plus a high-value target file. Exploitation is reliable, leaves no kernel logs, survives reboots, and bypasses common defenses because it operates at the filesystem allocation layer. Vendor-fixed kernels are available and immediate patching and rebooting are recommended.
