RefluXFS sfrutta una race condition di XFS per modificare file protetti e ottenere accesso root. Sistemi colpiti, verifica e patch.

CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root…