Qualys researchers identified CVE-2026-64600, a critical race condition in the Linux kernel's XFS filesystem copy-on-write path that allows local privilege escalation to root. The vulnerability affects major enterprise distributions like RHEL and Fedora, impacting over 16.4 million systems since its introduction in kernel 4.11. Exploitation is highly reliable, leaves no kernel logs, and bypasses SELinux Enforcing mode.
Background
The XFS filesystem is widely used in enterprise Linux environments for its performance and scalability, particularly with features like reflinks (copy-on-write). Local privilege escalation vulnerabilities in core filesystem components are critical as they allow unprivileged users to gain full system control.
- Source
- Lobsters
- Published
- Jul 23, 2026 at 04:24 AM
- Score
- 9.0 / 10