RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

2026-07-22T20:51:54Zee562037c2ec124785ff4345f53dd001a069222e8372c0314820c37ca4a61342
ai-vulnerability-discoveryautomated-remediationcisa-bod-26-04credential-reusefortibleedfortigatekernellinuxlocal-privilege-escalationmicrosoft-patch-tuesdayoracle-cpupatch-managementrace-conditionsecurity-researchselinuxsnap-confineubuntuvulnerability-disclosurexfs

What happened

Qualys Threat Research Unit published multiple security advisories and analyses: RefluXFS (CVE-2026-64600) — a race condition in the Linux XFS copy-on-write path that enables a local unprivileged user to overwrite protected files and escalate to root (affects systems including SELinux Enforcing); snap-confine (CVE-2026-8933) — a race condition introduced by hardening that allows local privilege escalation to full root on default Ubuntu Desktop installs (24.04, 25.10, 26.04); Oracle’s July 2026 Critical Patch Update addressing 1,449 vulnerabilities; Microsoft/Adobe July 2026 Patch Tuesday with

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
ee562037c2ec124785ff4345f53dd001a069222e8372c0314820c37ca4a61342
Enrichment time
2026-07-22T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.