New RefluXFS Linux flaw lets attackers gain root privileges

Summary

A newly disclosed vulnerability in the Linux kernel's XFS filesystem, identified as CVE-2026-64600, allows local attackers to gain root privileges. This nine-year-old race condition flaw enables the overwriting of protected files on affected systems.

IFF Assessment

FOE

The discovery of a vulnerability that allows local privilege escalation to root is bad news for defenders as it can be exploited to gain complete control of a system.

Severity

7.8 High (AI Estimated)

The CVSS score is estimated to be high due to the Local attack vector (AV:L) and the potential for full Confidentiality, Integrity, and Availability impact (C:H/I:H/A:H), allowing for root privilege escalation and system compromise.

Defender Context

This vulnerability highlights the persistent risk of older, undiscovered flaws within core system components like the Linux kernel. Defenders should prioritize patching or mitigating systems that utilize the XFS filesystem, especially in environments where local user access is a potential attack vector.

Read Full Story →