RefluXFS (CVE-2026-64600): XFS Race Condition Gives Any Local User Root
On July 22, Qualys published a Linux kernel advisory that anyone running shared hosting on a RHEL-family system should read before doing anything else: CVE-2026-64600, nicknamed RefluXFS. It is a local privilege escalation to root in the Linux kernel’s XFS filesystem, and the proof-of-concept Qualys published strips the root password from /etc/passwd in seconds — starting from an ordinary, unprivileged local account. The vulnerability has been sitting in the kernel since version 4.11, released in 2017. Nine years of shared hosting servers, VPS instances, and cloud nodes, quietly exposed. ...