RefluXFS (CVE-2026-64600): XFS Race Condition Gives Any Local User Root

On July 22, Qualys published a Linux kernel advisory that anyone running shared hosting on a RHEL-family system should read before doing anything else: CVE-2026-64600, nicknamed RefluXFS. It is a local privilege escalation to root in the Linux kernel’s XFS filesystem, and the proof-of-concept Qualys published strips the root password from /etc/passwd in seconds — starting from an ordinary, unprivileged local account. The vulnerability has been sitting in the kernel since version 4.11, released in 2017. Nine years of shared hosting servers, VPS instances, and cloud nodes, quietly exposed. ...

August 2, 2026 · 4 min

GhostLock (CVE-2026-43499): The 15-Year-Old Kernel Bug That Hands Anyone Root

A working proof-of-concept for CVE-2026-43499, nicknamed GhostLock, went public on July 7, 2026. It hands any unprivileged local user a root shell in about five seconds, and it works from inside a container to escape to the host. If you run Linux servers — shared hosting, VPS, or bare metal — this is the one to patch before anything else this week. What GhostLock is The bug lives in kernel/locking/rtmutex.c, on the futex priority-inheritance (PI) path. When the kernel handles a FUTEX_CMP_REQUEUE_PI requeue and detects a deadlock cycle, it rolls back with -EDEADLK by calling remove_waiter(). The problem: that helper clears pi_blocked_on on the wrong thread — not the sleeping thread it should be cleaning up, but the currently running task. That leaves a live thread holding a dangling pointer into already-freed kernel stack memory. Stack use-after-free. ...

July 16, 2026 · 4 min

DirtyClone (CVE-2026-43503): The Linux Kernel Flaw That Leaves No Trace

On June 25, 2026, JFrog Security Research published a working exploit walkthrough for a Linux kernel privilege escalation they named DirtyClone. Tracked as CVE-2026-43503 with a CVSS score of 8.8, it lets any local user on an unpatched system escalate to root — and the attack leaves nothing on disk for forensic tools to find. That combination should get a hosting operator’s attention. What the Bug Is The flaw lives in __pskb_copy_fclone(), a kernel function that copies network packets internally. When a packet is cloned, this function — and a handful of related fragment-transfer helpers — drops a safety flag called SKBFL_SHARED_FRAG. That flag marks packet memory as shared with a file on disk. Once it’s gone, the kernel no longer treats the memory as read-only, and an attacker can write to it. ...

June 28, 2026 · 4 min