Qualys researchers identified a critical Linux kernel vulnerability tracked as CVE-2026-64600. The flaw, named RefluXFS, has existed in the XFS filesystem since version 4.11.
This race condition allows unprivileged local users to gain full root privileges. Attackers can exploit the bug to overwrite protected system files such as /etc/passwd.
The vulnerability impacts major distributions including Red Hat Enterprise Linux, Oracle Linux, Amazon Linux, and Fedora. Qualys confirmed the exploit remains effective even on hardened systems.
Organizations must apply available patches immediately as no reliable temporary mitigations exist. The discovery underscores the company's specialized capabilities in vulnerability management and research.