- Sources: Qualys RefluXFS writeup, oss-security, CVE-2026-46331 (NVD), The Register, HN 49014458
- Summary: Two local-privilege-escalation flaws with public exploits reached root on Linux on 2026-07-22. Qualys disclosed RefluXFS (CVE-2026-64600), a race in the XFS copy-on-write path where concurrent
O_DIRECT writes to a reflinked file overwrite a shared page never made private, giving an unprivileged user root on volumes with reflink=1 (default on RHEL, Oracle Linux, and Amazon Linux). It affects kernels from v4.11 to unpatched current, with a demonstrated passwordless-root PoC on RHEL 10.2. Separately, an author-verified exploit for pedit-COW (CVE-2026-46331, disclosed June 2026) poisons the cached /bin/su binary via a tc act_pedit copy-on-write miss to get root on kernels up to 6.12.9 where unprivileged user namespaces are available. Both landed as the kernel CVE team published 432 CVEs in two days. - Comments: HN commenters note the reflink prerequisite limits RefluXFS to distros that default to it. On the flood, Akamai's Jan Schaumann is quoted that prioritizing individual kernel changes is no longer feasible and that automated frequent updates are the only workable defense.
- Why it matters: Both give a turnkey unprivileged-to-root path on widely deployed default configurations, and the CVE volume makes triage-by-CVE impractical for most operators.
- Follow-up: Watch for named fixed stable versions, distribution backports, and any CISA KEV additions.
send feedback on this story