RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)
2026-07-23T20:51:49Z•7ea4c92f2a012a09097ec87d5a14240d58a7dbd3332c1c936ff904906e00e9f9
ai-accelerated-discoveryautomated-remediationcisa-bod-26-04credential-exposurefortigateidentity-securitykernellinuxlocal-privilege-escalationmicrosoft-patch-tuesdayoracle-cpuqualys-trurace-conditionrootselinuxsnap-confineubuntuvulnerability-managementxfs
What happened
This Qualys blog feed highlights multiple high-impact vulnerability findings and security guidance. Notable discoveries from Qualys TRU include CVE-2026-64600, a race condition in the Linux XFS copy-on-write path that allows a local account to overwrite protected files and achieve root (effective even with SELinux Enforcing), and CVE-2026-8933, a snap-confine race-condition local privilege escalation affecting default Ubuntu Desktop installations. Other entries summarize large-scale vendor patch releases (Oracle July 2026 CPU addressing ~1449 vulnerabilities; Microsoft/Adobe July 2026 Patch T
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- 7ea4c92f2a012a09097ec87d5a14240d58a7dbd3332c1c936ff904906e00e9f9
- Enrichment time
- 2026-07-23T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.