Linux Kernel Confronts Critical XFS Root‑Escalation Flaw and Flood of CVEs
A race‑condition bug in the XFS filesystem, dubbed RefluXFS (CVE‑2026‑64600), allows an unprivileged local user to gain full root access on systems running Linux kernel 4.11 or later with the reflink feature enabled. Qualys estimates that more than 16.4 million Linux deployments, including RHEL, CentOS, Oracle Linux, Rocky, AlmaLinux, CloudLinux and Amazon Linux, are vulnerable. The exploit is highly reliable, leaves no kernel log output, and persists across reboots.
In the same period, the Linux kernel community was hit by an unprecedented surge of security disclosures, with 432 CVEs published over a single weekend, straining administrators and prompting the release of Linux 7.2‑rc4, which contains numerous fixes—many identified by AI‑driven bug‑hunting tools. Linus Torvalds publicly reaffirmed that Linux will not adopt an anti‑AI stance, stating the project will embrace AI as a useful development aid while maintaining human responsibility for contributions.