<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=refluxfs%252525252525252525252525252525252520linux%252525252525252525252525252525252520kernel%252525252525252525252525252525252520local%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 08 Aug 2026 10:36:17 +0200</lastBuildDate>
<pubDate>Sat, 08 Aug 2026 10:36:17 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=refluxfs%252525252525252525252525252525252520linux%252525252525252525252525252525252520kernel%252525252525252525252525252525252520local%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=refluxfs%252525252525252525252525252525252520linux%252525252525252525252525252525252520kernel%252525252525252525252525252525252520local%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[RefluXFS: Kritische Linux-Kernel-Schwachstelle (CVE-2026-64600)]]></title>
<description><![CDATA[Sicherheitsexperten von der Qualys Threat Research Unit (TRU) haben eine kritische Schwachstelle (CVE-2026-64600) im Linux-Kernel entdeckt. Die RefluXFS genannte Schwachstelle ermöglicht einem Nutzer Root-Berechtigungen zu erlangen. Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum L...]]></description>
<link>https://tsecurity.de/de/3705905/it-nachrichten/refluxfs-kritische-linux-kernel-schwachstelle-cve-2026-64600/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705905/it-nachrichten/refluxfs-kritische-linux-kernel-schwachstelle-cve-2026-64600/</guid>
<pubDate>Wed, 05 Aug 2026 15:10:29 +0200</pubDate>
<content:encoded><![CDATA[Sicherheitsexperten von der Qualys Threat Research Unit (TRU) haben eine kritische Schwachstelle (CVE-2026-64600) im Linux-Kernel entdeckt. Die RefluXFS genannte Schwachstelle ermöglicht einem Nutzer Root-Berechtigungen zu erlangen. Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in … <a href="https://borncity.com/blog/2026/08/03/refluxfs-kritische-linux-kernel-schwachstelle-cve-2026-64600/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/08/03/refluxfs-kritische-linux-kernel-schwachstelle-cve-2026-64600/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nächste Linux-Lücke ermöglicht Root-Rechte]]></title>
<description><![CDATA[Die Sicherheitslücke „RefluXFS“ ermöglicht es Angreifern, sich spurlos Root-Rechte unter Linux zu verschaffen, ganz ohne Kernel-Log-Einträge. Millionen Systeme sind potenziell betroffen, sofortiges Patchen ist erforderlich.]]></description>
<link>https://tsecurity.de/de/3700104/it-security-nachrichten/naechste-linux-luecke-ermoeglicht-root-rechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700104/it-security-nachrichten/naechste-linux-luecke-ermoeglicht-root-rechte/</guid>
<pubDate>Mon, 03 Aug 2026 10:17:51 +0200</pubDate>
<content:encoded><![CDATA[Die Sicherheitslücke „RefluXFS“ ermöglicht es Angreifern, sich spurlos Root-Rechte unter Linux zu verschaffen, ganz ohne Kernel-Log-Einträge. Millionen Systeme sind potenziell betroffen, sofortiges Patchen ist erforderlich.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rechteausweitung RefluXFS gefährdet Linux-Systeme mit XFS-Dateisystem]]></title>
<description><![CDATA[Eine Schwachstelle im Linux-Kernel namens RefluXFS ermöglicht lokalen Nutzern Root-Rechte auf XFS-Dateisystemen. Patches stehen zur Verfügung.

Tags: #Cyber Security | #Linux]]></description>
<link>https://tsecurity.de/de/3694278/it-security-nachrichten/rechteausweitung-refluxfs-gefaehrdet-linux-systeme-mit-xfs-dateisystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694278/it-security-nachrichten/rechteausweitung-refluxfs-gefaehrdet-linux-systeme-mit-xfs-dateisystem/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:54 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1000" height="563" src="https://www.it-daily.net/wp-content/uploads/2022/09/Linux-Malware_Quelle-Stanislaw_Mikulski_1343898593_1437471722_1000.jpeg" class="attachment-full size-full wp-post-image" alt="Linux" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2022/09/Linux-Malware_Quelle-Stanislaw_Mikulski_1343898593_1437471722_1000.jpeg 1000w, https://www.it-daily.net/wp-content/uploads/2022/09/Linux-Malware_Quelle-Stanislaw_Mikulski_1343898593_1437471722_1000-300x169.jpeg 300w, https://www.it-daily.net/wp-content/uploads/2022/09/Linux-Malware_Quelle-Stanislaw_Mikulski_1343898593_1437471722_1000-768x432.jpeg 768w" sizes="(max-width: 1000px) 100vw, 1000px" title="Rechteausweitung RefluXFS gefährdet Linux-Systeme mit XFS-Dateisystem 1"></p>
    Eine Schwachstelle im Linux-Kernel namens RefluXFS ermöglicht lokalen Nutzern Root-Rechte auf XFS-Dateisystemen. Patches stehen zur Verfügung.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/linux">#Linux</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rechteausweitung RefluXFS gefährdet Linux-Systeme mit XFS-Dateisystem - it-daily.net]]></title>
<description><![CDATA[Patches stehen zur Verfügung. Sicherheitsforscher des Unternehmens Qualys haben unter der Bezeichnung RefluXFS beziehungsweise CVE-2026-64600 eine ...]]></description>
<link>https://tsecurity.de/de/3694270/it-security-nachrichten/rechteausweitung-refluxfs-gefaehrdet-linux-systeme-mit-xfs-dateisystem-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694270/it-security-nachrichten/rechteausweitung-refluxfs-gefaehrdet-linux-systeme-mit-xfs-dateisystem-it-dailynet/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:43 +0200</pubDate>
<content:encoded><![CDATA[Patches stehen zur Verfügung. Sicherheitsforscher des Unternehmens Qualys haben unter der Bezeichnung RefluXFS beziehungsweise CVE-2026-64600 eine ...]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff]]></title>
<description><![CDATA[Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (Sicherheitslücke, Fedora)]]></description>
<link>https://tsecurity.de/de/3694198/it-security-nachrichten/refluxfs-kernel-bug-verleiht-auf-millionen-von-linux-systemen-root-zugriff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694198/it-security-nachrichten/refluxfs-kernel-bug-verleiht-auf-millionen-von-linux-systemen-root-zugriff/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:03 +0200</pubDate>
<content:encoded><![CDATA[Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>, <a href="https://www.golem.de/specials/fedora/">Fedora</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211245&amp;page=1&amp;ts=1784883902" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: Neue XFS-Kernel-Schwachstelle ermöglicht Root-Rechte auf betroffenen RHEL-Installationen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Kernel-Schwachstelle namens RefluXFS (CVE-2026-64600) erlaubt es lokalen Angreifern, auf bestimmten Systemen Root-Rechte zu erlangen. Entscheidend ist dabei XFS-Reflink-Unterstützung in Kombination mit einem speziellen Race-Condition-Fenster im Block-Layer. Besond...]]></description>
<link>https://tsecurity.de/de/3692727/it-security-nachrichten/refluxfs-neue-xfs-kernel-schwachstelle-ermoeglicht-root-rechte-auf-betroffenen-rhel-installationen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692727/it-security-nachrichten/refluxfs-neue-xfs-kernel-schwachstelle-ermoeglicht-root-rechte-auf-betroffenen-rhel-installationen/</guid>
<pubDate>Sat, 25 Jul 2026 01:07:32 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/refluxfs-xfs-reflink-root-rhel-schwachstelle-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neue Kernel-Schwachstelle namens RefluXFS (CVE-2026-64600) erlaubt es lokalen Angreifern, auf bestimmten Systemen Root-Rechte zu erlangen. Entscheidend ist dabei XFS-Reflink-Unterstützung in Kombination mit einem speziellen Race-Condition-Fenster im Block-Layer. Besonders relevant sind Standardinstallationen von Red Hat Enterprise Linux und mehreren Derivaten, darunter Fedora Server und Amazon Linux. Wer nur anhand von “bisherige […]</p>
<div><a href="https://www.it-boltwise.de/refluxfs-neue-xfs-kernel-schwachstelle-ermoeglicht-root-rechte-auf-betroffenen-rhel-installationen.html">... den vollständigen Artikel <strong>»RefluXFS: Neue XFS-Kernel-Schwachstelle ermöglicht Root-Rechte auf betroffenen RHEL-Installationen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/refluxfs-neue-xfs-kernel-schwachstelle-ermoeglicht-root-rechte-auf-betroffenen-rhel-installationen.html">RefluXFS: Neue XFS-Kernel-Schwachstelle ermöglicht Root-Rechte auf betroffenen RHEL-Installationen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)]]></title>
<description><![CDATA[submitted by    /u/FryBoyter   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3692667/linux-tipps/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692667/linux-tipps/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600/</guid>
<pubDate>Sat, 25 Jul 2026 00:11:39 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/FryBoyter"> /u/FryBoyter </a> <br> <span><a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v56hde/refluxfs_a_linux_kernel_local_privilege/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff - Golem.de]]></title>
<description><![CDATA[Seminar: IT-Security-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop · zum Kurs. backwards 1 2 3 forwards. Damit lässt sich CVE ...]]></description>
<link>https://tsecurity.de/de/3692359/it-security-nachrichten/refluxfs-kernel-bug-verleiht-auf-millionen-von-linux-systemen-root-zugriff-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692359/it-security-nachrichten/refluxfs-kernel-bug-verleiht-auf-millionen-von-linux-systemen-root-zugriff-golemde/</guid>
<pubDate>Fri, 24 Jul 2026 21:08:51 +0200</pubDate>
<content:encoded><![CDATA[Seminar: <b>IT</b>-<b>Security</b>-Awareness für Systemadministratoren: virtueller Ein-Tages-Workshop · zum Kurs. backwards 1 2 3 forwards. Damit lässt sich CVE ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Unprivilegierte lokale Nutzer erlangen Root-Rechte durch Linux-Kernel-Schwachstelle „RefluXFS“]]></title>
<description><![CDATA[Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in großem Umfang im Einsatz haben ...]]></description>
<link>https://tsecurity.de/de/3691644/it-security-nachrichten/unprivilegierte-lokale-nutzer-erlangen-root-rechte-durch-linux-kernel-schwachstelle-refluxfs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691644/it-security-nachrichten/unprivilegierte-lokale-nutzer-erlangen-root-rechte-durch-linux-kernel-schwachstelle-refluxfs/</guid>
<pubDate>Fri, 24 Jul 2026 15:11:22 +0200</pubDate>
<content:encoded><![CDATA[Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in großem Umfang im Einsatz haben ...]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: Gefährlicher Kernel-Bug verleiht Root-Zugriff unter Linux - Golem.de]]></title>
<description><![CDATA[... Windows Server 2022 (E-Learning). E-Learning: Failover Clustering mit Windows Server 2022 (E-Learning) · zum Kurs. IT-Risikomanagement-Schulung ...]]></description>
<link>https://tsecurity.de/de/3691395/windows-server/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691395/windows-server/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux-golemde/</guid>
<pubDate>Fri, 24 Jul 2026 13:31:56 +0200</pubDate>
<content:encoded><![CDATA[... <b>Windows Server</b> 2022 (E-Learning). E-Learning: Failover Clustering mit <b>Windows Server</b> 2022 (E-Learning) · zum Kurs. IT-Risikomanagement-Schulung ...]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS: Gefährlicher Kernel-Bug verleiht Root-Zugriff unter Linux]]></title>
<description><![CDATA[Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (Sicherheitslücke, Fedora)]]></description>
<link>https://tsecurity.de/de/3691111/it-nachrichten/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691111/it-nachrichten/refluxfs-gefaehrlicher-kernel-bug-verleiht-root-zugriff-unter-linux/</guid>
<pubDate>Fri, 24 Jul 2026 11:24:28 +0200</pubDate>
<content:encoded><![CDATA[Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>, <a href="https://www.golem.de/specials/fedora/">Fedora</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211245&amp;page=1&amp;ts=1784883902" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Dissecting RefluXFS: How CVE-2026-64600 turns an XFS race into root]]></title>
<description><![CDATA[RefluXFS (CVE-2026-64600) is a Linux kernel local privilege escalation vulnerability rooted in a race condition within XFS. This write-up explores the vulnerability's internals, exploitation requirements, affected kernel versions, patch analysis, and the defensive considerations for identifying a...]]></description>
<link>https://tsecurity.de/de/3690357/it-security-nachrichten/dissecting-refluxfs-how-cve-2026-64600-turns-an-xfs-race-into-root/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690357/it-security-nachrichten/dissecting-refluxfs-how-cve-2026-64600-turns-an-xfs-race-into-root/</guid>
<pubDate>Fri, 24 Jul 2026 00:27:47 +0200</pubDate>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/security/comments/1v4667n/dissecting_refluxfs_how_cve202664600_turns_an_xfs/"> <img src="https://external-preview.redd.it/kbJOm-dCTCPQSY7TdGfXHMRWE7QW-rW_YA6cso-Qcl8.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=fb5d33909c597e85720004731870120fd5799de9" alt="Dissecting RefluXFS: How CVE-2026-64600 turns an XFS race into root" title="Dissecting RefluXFS: How CVE-2026-64600 turns an XFS race into root"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>RefluXFS (CVE-2026-64600) is a Linux kernel local privilege escalation vulnerability rooted in a race condition within XFS. This write-up explores the vulnerability's internals, exploitation requirements, affected kernel versions, patch analysis, and the defensive considerations for identifying and mitigating exposure.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NapierPalm"> /u/NapierPalm </a> <br> <span><a href="https://thecybersecguru.com/news/refluxfs-cve-2026-64600-linux-xfs-root-vulnerability/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1v4667n/dissecting_refluxfs_how_cve202664600_turns_an_xfs/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux XFS has a decade-old race condition allowing full root access]]></title>
<description><![CDATA[Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.



The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without ...]]></description>
<link>https://tsecurity.de/de/3689585/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689585/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 17:59:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linux systems using the XFS <a href="https://www.networkworld.com/article/3631604/linux-filesystems-ext4-btrfs-xfs-zfs-and-more.html">filesystem</a> suffer from a race condition that could enable an unprivileged local user to gain full root access.</p>



<p class="wp-block-paragraph">The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.</p>



<p class="wp-block-paragraph">According to Qualys Threat Research Unit (TRU), there was a way around the file write protections reflink depends on. The bypass has existed in kernel versions since 2017 before a <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e705d81a7193dd19e69b8e2bad4696d78a4ea075" target="_blank" rel="noreferrer noopener">patch was made available</a> last week.</p>



<p class="wp-block-paragraph">“Using this vulnerability, a process running as an ordinary, unprivileged user can trigger the flaw and gain the ability to overwrite any readable file on an XFS volume at the block layer,” <a href="https://www.linkedin.com/in/saeedabbasi/" target="_blank" rel="noreferrer noopener">Saeed Abbasi</a>, head of Qualys TRU, said in a blog post about the vulnerability, which he calls  <a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600" target="_blank" rel="noreferrer noopener">RefluXFS</a>. “Exploitation is highly reliable and leaves no kernel log output.”</p>



<p class="wp-block-paragraph">Qualys estimated that the issue affects more than 16.4 million systems, primarily enterprise Linux deployments that use XFS with reflink enabled by default.</p>



<h2 class="wp-block-heading">Race winner gets root in buggy file operation</h2>



<p class="wp-block-paragraph">The vulnerability, tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2026-64600" target="_blank" rel="noreferrer noopener">CVE-2026-64600</a>, stemmed from the way XFS handles copy-on-write operations for reflinked files. Normally, when two files share the same storage block, as in the case of an original file and the reflinked clone, XFS allocates a new storage block before any data modification, so the original file remains unchanged.</p>



<p class="wp-block-paragraph">However, a race condition occurs when two concurrent writes on the reflink file are initiated, confusing the filesystem into modifying the original file. “The change is made directly on disk, persists across reboots, and produces no kernel log output,” Qualys said in an <a href="https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt" target="_blank" rel="noreferrer noopener">advisory</a>.</p>



<p class="wp-block-paragraph">The issue is exploitable when Linux 4.11+, XFS with reflink enabled, and a shared filesystem layout are all present. It is assigned a high severity CVSS of 7.8 out of 10 as an exploit only needs read access to a target file before creating a reflink clone under a writable directory on the same XFS filesystem.</p>



<h2 class="wp-block-heading">Linux distributions affected by RefluXFS</h2>



<p class="wp-block-paragraph">The vulnerability has been present in every mainline and stable Linux kernel since the release of version 4.11 in 2017, and requires no special capabilities or non-default configurations, Qualys said.</p>



<p class="wp-block-paragraph">Affected Linux distributions include RHEL 8,9 and 10, CentOS Stream 8,9, and 10, Oracle Linux 8,9,10, Rocky and AlmaLinux 8,9, and 10, CloudLinux 8,9, and 10, Amazon Linux 2023 and Amazon Linux 2 AMIs from December 2022 onward, Fedora Server 31+, and Debian, Ubuntu and SUSE installations where XFS was manually selected.</p>



<p class="wp-block-paragraph">Usual kernel hardening practices, including memory protection features like <a href="https://www.csoonline.com/article/559839/self-protection-is-key-to-linux-kernel-security.html">Kernel Address Space Layout Randomization</a> (KASLR), Supervisor Mode Access Prevention (SMAP), and Supervisor Mode Execution Prevention (SMEP), are ineffective as they are all aimed at different attack surfaces. Even a kernel lockdown does nothing to stop the affected path, Qualys noted.</p>



<p class="wp-block-paragraph">“SELinux doesn’t block the affected path in testing, and seccomp profiles are no barrier as long as they permit write and ioctl, which ordinary profiles do,” Abbasi explained. Immediate kernel patching and a full reboot are the only reliable mitigations, he added.</p>



<p class="wp-block-paragraph">A fix was merged into the upstream Linux kernel source tree on July 16 as commit “2f4acd0,” after which Linux distributions began backporting the patch into their own supported kernel releases.</p>



<p class="wp-block-paragraph">Organizations running affected XFS deployments should apply their Linux vendor’s latest kernel updates and reboot affected systems once fixed kernels become available.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux XFS has a decade-old race condition allowing full root access]]></title>
<description><![CDATA[Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.



The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without ...]]></description>
<link>https://tsecurity.de/de/3689584/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689584/it-security-nachrichten/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 17:58:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linux systems using the XFS <a href="https://www.networkworld.com/article/3631604/linux-filesystems-ext4-btrfs-xfs-zfs-and-more.html">filesystem</a> suffer from a race condition that could enable an unprivileged local user to gain full root access.</p>



<p class="wp-block-paragraph">The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.</p>



<p class="wp-block-paragraph">According to Qualys Threat Research Unit (TRU), there was a way around the file write protections reflink depends on. The bypass has existed in kernel versions since 2017 before a <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e705d81a7193dd19e69b8e2bad4696d78a4ea075" target="_blank" rel="noreferrer noopener">patch was made available</a> last week.</p>



<p class="wp-block-paragraph">“Using this vulnerability, a process running as an ordinary, unprivileged user can trigger the flaw and gain the ability to overwrite any readable file on an XFS volume at the block layer,” <a href="https://www.linkedin.com/in/saeedabbasi/" target="_blank" rel="noreferrer noopener">Saeed Abbasi</a>, head of Qualys TRU, said in a blog post about the vulnerability, which he calls  <a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600" target="_blank" rel="noreferrer noopener">RefluXFS</a>. “Exploitation is highly reliable and leaves no kernel log output.”</p>



<p class="wp-block-paragraph">Qualys estimated that the issue affects more than 16.4 million systems, primarily enterprise Linux deployments that use XFS with reflink enabled by default.</p>



<h2 class="wp-block-heading">Race winner gets root in buggy file operation</h2>



<p class="wp-block-paragraph">The vulnerability, tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2026-64600" target="_blank" rel="noreferrer noopener">CVE-2026-64600</a>, stemmed from the way XFS handles copy-on-write operations for reflinked files. Normally, when two files share the same storage block, as in the case of an original file and the reflinked clone, XFS allocates a new storage block before any data modification, so the original file remains unchanged.</p>



<p class="wp-block-paragraph">However, a race condition occurs when two concurrent writes on the reflink file are initiated, confusing the filesystem into modifying the original file. “The change is made directly on disk, persists across reboots, and produces no kernel log output,” Qualys said in an <a href="https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt" target="_blank" rel="noreferrer noopener">advisory</a>.</p>



<p class="wp-block-paragraph">The issue is exploitable when Linux 4.11+, XFS with reflink enabled, and a shared filesystem layout are all present. It is assigned a high severity CVSS of 7.8 out of 10 as an exploit only needs read access to a target file before creating a reflink clone under a writable directory on the same XFS filesystem.</p>



<h2 class="wp-block-heading">Linux distributions affected by RefluXFS</h2>



<p class="wp-block-paragraph">The vulnerability has been present in every mainline and stable Linux kernel since the release of version 4.11 in 2017, and requires no special capabilities or non-default configurations, Qualys said.</p>



<p class="wp-block-paragraph">Affected Linux distributions include RHEL 8,9 and 10, CentOS Stream 8,9, and 10, Oracle Linux 8,9,10, Rocky and AlmaLinux 8,9, and 10, CloudLinux 8,9, and 10, Amazon Linux 2023 and Amazon Linux 2 AMIs from December 2022 onward, Fedora Server 31+, and Debian, Ubuntu and SUSE installations where XFS was manually selected.</p>



<p class="wp-block-paragraph">Usual kernel hardening practices, including memory protection features like <a href="https://www.csoonline.com/article/559839/self-protection-is-key-to-linux-kernel-security.html">Kernel Address Space Layout Randomization</a> (KASLR), Supervisor Mode Access Prevention (SMAP), and Supervisor Mode Execution Prevention (SMEP), are ineffective as they are all aimed at different attack surfaces. Even a kernel lockdown does nothing to stop the affected path, Qualys noted.</p>



<p class="wp-block-paragraph">“SELinux doesn’t block the affected path in testing, and seccomp profiles are no barrier as long as they permit write and ioctl, which ordinary profiles do,” Abbasi explained. Immediate kernel patching and a full reboot are the only reliable mitigations, he added.</p>



<p class="wp-block-paragraph">A fix was merged into the upstream Linux kernel source tree on July 16 as commit “2f4acd0,” after which Linux distributions began backporting the patch into their own supported kernel releases.</p>



<p class="wp-block-paragraph">Organizations running affected XFS deployments should apply their Linux vendor’s latest kernel updates and reboot affected systems once fixed kernels become available.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4200802/linux-xfs-has-a-decade-old-race-condition-allowing-full-root-access.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New RefluXFS Linux flaw lets attackers gain root privileges]]></title>
<description><![CDATA[A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]]]></description>
<link>https://tsecurity.de/de/3688952/it-security-nachrichten/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688952/it-security-nachrichten/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/</guid>
<pubDate>Thu, 23 Jul 2026 13:59:21 +0200</pubDate>
<content:encoded><![CDATA[A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs]]></title>
<description><![CDATA[RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux…
Read more →
The post Nine-Year-Old ...]]></description>
<link>https://tsecurity.de/de/3688653/it-security-nachrichten/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688653/it-security-nachrichten/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/</guid>
<pubDate>Thu, 23 Jul 2026 12:10:55 +0200</pubDate>
<content:encoded><![CDATA[<p>RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/">Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-23 12h : 15 posts]]></title>
<description><![CDATA[15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…
Read more →
The post IT Security News Hourly Summary 2026-07-23...]]></description>
<link>https://tsecurity.de/de/3688649/it-security-nachrichten/it-security-news-hourly-summary-2026-07-23-12h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688649/it-security-nachrichten/it-security-news-hourly-summary-2026-07-23-12h-15-posts/</guid>
<pubDate>Thu, 23 Jul 2026 12:10:35 +0200</pubDate>
<content:encoded><![CDATA[<p>15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-23-12h-15-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-23-12h-15-posts/">IT Security News Hourly Summary 2026-07-23 12h : 15 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs]]></title>
<description><![CDATA[RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server,...]]></description>
<link>https://tsecurity.de/de/3688609/it-security-nachrichten/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688609/it-security-nachrichten/nine-year-old-refluxfs-linux-flaw-gives-local-users-root-on-default-rhel-installs/</guid>
<pubDate>Thu, 23 Jul 2026 12:01:01 +0200</pubDate>
<content:encoded><![CDATA[RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.

The company demonstrated the race]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access]]></title>
<description><![CDATA[A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3688182/it-security-nachrichten/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688182/it-security-nachrichten/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 08:55:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/">Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access]]></title>
<description><![CDATA[A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reporte...]]></description>
<link>https://tsecurity.de/de/3688129/it-security-nachrichten/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688129/it-security-nachrichten/critical-refluxfs-linux-kernel-flaw-lets-local-attackers-gain-root-access/</guid>
<pubDate>Thu, 23 Jul 2026 08:11:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017. […]</p>
<p>The post <a href="https://gbhackers.com/critical-refluxfs-linux-kernel-flaw/">Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical XFS Race Condition Enables Linux Privilege Escalation to Root]]></title>
<description><![CDATA[A newly disclosed CVE-2026-64600, dubbed “RefluXFS,” a critical race condition in the Linux kernel’s XFS filesystem that allows unprivileged local users to escalate to full root privileges. The flaw affects any Linux distribution shipping an XFS root filesystem with reflink enabled, including def...]]></description>
<link>https://tsecurity.de/de/3688024/it-security-nachrichten/critical-xfs-race-condition-enables-linux-privilege-escalation-to-root/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688024/it-security-nachrichten/critical-xfs-race-condition-enables-linux-privilege-escalation-to-root/</guid>
<pubDate>Thu, 23 Jul 2026 07:12:41 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly disclosed CVE-2026-64600, dubbed “RefluXFS,” a critical race condition in the Linux kernel’s XFS filesystem that allows unprivileged local users to escalate to full root privileges. The flaw affects any Linux distribution shipping an XFS root filesystem with reflink enabled, including default installations of RHEL, Oracle Linux, Amazon Linux, and Fedora. Qualys estimates over […]</p>
<p>The post <a href="https://cyberpress.org/critical-xfs-race-condition/">Critical XFS Race Condition Enables Linux Privilege Escalation to Root</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access]]></title>
<description><![CDATA[A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in…
Read more →
The post RefluXFS Linux...]]></description>
<link>https://tsecurity.de/de/3687328/it-security-nachrichten/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687328/it-security-nachrichten/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/</guid>
<pubDate>Wed, 22 Jul 2026 20:38:55 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/">RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access]]></title>
<description><![CDATA[A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode. The vulnerability tr...]]></description>
<link>https://tsecurity.de/de/3687240/it-security-nachrichten/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687240/it-security-nachrichten/refluxfs-linux-kernel-vulnerability-lets-attackers-gain-root-access/</guid>
<pubDate>Wed, 22 Jul 2026 20:24:14 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode. The vulnerability tracked as CVE-2026-64600 uncovered by Qualys Threat Research Unit (TRU) exploits […]</p>
<p>The post <a href="https://cybersecuritynews.com/refluxfs-linux-kernel-vulnerability/">RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,15ms -->