< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Critical Linux Kernel Flaw RefluXFS Exposes Millions of Systems

Qualys reported a critical vulnerability in the Linux kernel, designated CVE‑2026‑64600 and nicknamed “RefluXFS.” The flaw is a race condition in the XFS filesystem’s copy‑on‑write path that lets a local user overwrite protected files and gain root privileges, even when SELinux is enforcing. Qualys estimates the issue could affect more than 16.4 million installations, including Red Hat Enterprise Linux, Oracle Linux, Amazon Linux and Fedora, and recommends immediate kernel updates.

AlmaLinux issued two separate advisories: an important security update for AlmaLinux 10 that patches CVE‑2026‑46323, a use‑after‑free bug in the net/gro subsystem, and a bug‑fix update for AlmaLinux 9 that resolves XFS reflink data‑corruption problems. Across the Linux ecosystem, major distributions such as Debian, Fedora, Mageia, Oracle and SUSE released a flood of security patches for dozens of packages, ranging from kernel components to user‑space tools.

Separately, a use‑after‑free flaw in the Windows bfs.sys driver (CVE‑2026‑50458) was patched in the latest Patch Tuesday release, addressing a memory‑management error that could enable privilege escalation on millions of Windows devices.

Entities

AlmaLinux · Linux kernel · Microsoft · Qualys Threat Research Unit · Saeed Abbasi

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] AlmaLinux 9 bug‑fix ALBA‑2026:39332 resolves XFS reflink data‑corruption in version 9.8.z. www.linuxcompatible.org
  • [○ 1 SOURCE] CVE‑2026‑50458 is a use‑after‑free vulnerability in the Windows bfs.sys driver that can enable privilege escalation. dev.to
  • [○ 1 SOURCE] AlmaLinux 10 security update ALSA‑2026:44270 patches CVE‑2026‑46323, a use‑after‑free vulnerability in the net/gro subsystem. www.linuxcompatible.org
  • [○ 1 SOURCE] Multiple Linux distributions released security updates for dozens of packages, including kernel, OpenSSL, Java, and various system utilities. techrights.org
  • [○ 1 SOURCE] RefluXFS may affect over 16.4 million systems, including RHEL, Oracle Linux, Amazon Linux and Fedora. techxmedia.com
  • [○ 1 SOURCE] CVE‑2026‑64600 (RefluXFS) is a Linux kernel XFS race condition that allows local privilege escalation to root. techxmedia.com
  • [○ 1 SOURCE] The Windows bfs.sys vulnerability was patched in the latest Patch Tuesday release. dev.to