Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    Kazakhstan Moves To Build A National Crypto Reserve Funded By Bitcoin Miners

    July 23, 2026

    NASA Astronaut Chris Williams Closes Out Space Station Mission

    July 23, 2026

    ZPMC starts building multipurpose CLV for Far East Cable

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Kazakhstan Moves To Build A National Crypto Reserve Funded By Bitcoin Miners
    • NASA Astronaut Chris Williams Closes Out Space Station Mission
    • ZPMC starts building multipurpose CLV for Far East Cable
    • The Guardian view on Ukraine’s challenges, inside and out: tensions at home arise from the struggle against Russia | Editorial
    • Fake image of Ryanair plane after passenger was half sucked out of window circulates – Full Fact
    • Why I Sought Out a Taliban Commander I Had Fought
    • Canada pushes new UK government to join defense bank – POLITICO
    • Andy Burnham could easily ignore the UK’s falling aid commitment. He would be wise not to | Halima Begum
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    New RefluXFS Linux flaw lets attackers gain root privileges

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.

    Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later, with a directory writable by an unprivileged local user, and a high-value target (a root-owned configuration file or SUID-root binary).

    Also, standard defenses (including the Security-Enhanced Linux SELinux kernel security module, kernel lockdown, container isolation mechanisms, and memory-protection features like KASLR, SMEP, and SMAP) don’t block RefluXFS attacks because the flaw operates at the filesystem allocation layer, below where those protections apply.

    image

    According to Qualys, exploitation is highly reliable, leaves no kernel log output, and the on-disk modification survives a system reboot.

    “The attacker reflink-clones a target file (for example /etc/passwd, or a SUID-root binary such as /usr/bin/su) into a scratch file they own, then races concurrent O_DIRECT writes on that scratch file,” the Qualys TRU team explains in a detailed technical write-up published on Wednesday.

    “A lock-drop window in the kernel’s copy-on-write allocation path lets one of those writes land, not in the attacker’s own storage, but in the physical block that still backs the original file. The change is made directly on disk, persists across reboot, produces no kernel log output, and does not touch the target file’s inode — so a modified SUID-root binary keeps its SUID bit.”

    RefluXFS has existed since kernel version 4.11, after being introduced in February 2017 by commit 3c68d44a2b49. It has been present in every mainline and stable kernel since and was patched on July 16 after commit 2f4acd0was merged into the Linux kernel source tree.

    The list of impacted Linux distros includes Red Hat Enterprise Linux (RHEL), Oracle Linux, Amazon Linux and Fedora, as well as CentOS Stream, Rocky Linux, AlmaLinux and CloudLinux.

    Qualys estimates that it potentially affects more than 16.4 million systems based on analysis using its Cybersecurity Asset Management software.

    Saeed Abbasi, the head of Qualys’ Threat Research Unit, says the discovery emerged from a research initiative between Qualys and Anthropic, in which researchers integrated the AI model Claude Mythos Preview into their manual audit workflow.

    The Claude Mythos Preview was tasked with hunting for a race condition resembling the “Dirty COW” vulnerability class, and after iterative refinement identified the flaw in XFS and generated a functional proof-of-concept. Abbasi added that the Qualys security researchers then reviewed the model’s reasoning, reproduced the exploit, and independently verified all technical claims before coordinating disclosure with kernel maintainers.

    “Immediate kernel patching is recommended to neutralize this vulnerability. Exploitation succeeds consistently under standard hardening settings, and the on-disk modification survives a system reboot,” said Abbasi.

    “Vendor-fixed kernels are now available and being backported to enterprise distributions. Organizations should prioritize patching exposed and multi-tenant systems and ensure a reboot to verify the update. As of now, there are no reliable or practical mitigations or temporary configuration changes available.”

    RefluXFS is the latest in a long series of Linux privilege escalation vulnerabilities disclosed since the start of the year, including CIFSwitch, PinTheft, Copy Fail, Dirty Frag, Fragnesia, Pack2TheRoot, and DirtyDecrypt/DirtyCBC.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Attackers Flaw gain lets Linux privileges RefluXFS Root
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    EU fines Google $1 billion for search, app store antitrust violations

    Microsoft’s 3-day patching directive comes with added operational risk

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    New Check Point Zero-Day Vulnerability Exploited in the Wild

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    Adobe Chrome extension flaw let sites access private WhatsApp chats

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Kazakhstan Moves To Build A National Crypto Reserve Funded By Bitcoin Miners

    July 23, 2026

    NASA Astronaut Chris Williams Closes Out Space Station Mission

    July 23, 2026

    ZPMC starts building multipurpose CLV for Far East Cable

    July 23, 2026

    The Guardian view on Ukraine’s challenges, inside and out: tensions at home arise from the struggle against Russia | Editorial

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Kazakhstan Moves To Build A National Crypto Reserve Funded By Bitcoin Miners

    July 23, 2026

    NASA Astronaut Chris Williams Closes Out Space Station Mission

    July 23, 2026

    ZPMC starts building multipurpose CLV for Far East Cable

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.