RefluXFS Linux kernel vulnerability enables root privilege escalation through nine-year-old race condition

A race condition in the XFS filesystem, present in the Linux kernel for nine years, allows local attackers to overwrite protected files and gain root access.

Abstract illustration of layered filesystem architecture with a vulnerability gap
AI-generated illustration · Sylvaris

Nine-Year Flaw in Core Filesystem

A race condition vulnerability in the Linux kernel's XFS filesystem, designated CVE-2026-64600, has been present in production systems for nine years. The flaw allows local attackers to overwrite protected files and escalate to root privileges.

The vulnerability affects the XFS filesystem, a widely deployed journaling filesystem used across enterprise Linux deployments. Race conditions occur when two processes access shared resources simultaneously, creating windows of opportunity for exploitation.

Local Access Required

The vulnerability requires local access to exploit, meaning attackers must already have some level of system access. However, it provides a path to full root privileges from limited user accounts.

Organizations using XFS on Linux systems should prioritize kernel updates. The nine-year presence suggests many production systems remain unpatched, particularly in environments with conservative update policies.

sources
more in Security
msaRAT malware routes command traffic through Chrome and Edge browsers Chaos ransomware operators are hiding malicious command traffic by routing it through legitimate browser processes, complicating detection. Google adds selfie video verification for account recovery Google's new biometric recovery option provides account access when traditional two-factor authentication methods are unavailable. Check Point SmartConsole zero-day under active exploitation Active exploitation of administrative interface zero-days enables attackers to compromise enterprise network security infrastructure at scale.