< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Linux kernel vulnerability RefluXFS affects 16 million systems

A critical vulnerability, dubbed RefluXFS (CVE-2026-64600), has been discovered in the Linux kernel, potentially exposing over 16 million systems. The flaw has existed since version 4.11, released in 2017.

Discovered by the Qualys Threat Research Unit through Anthropic’s Glasswing project, the vulnerability involves a race condition in the XFS filesystem's copy-on-write path. It allows a local user without administrative privileges to overwrite any executable file on a volume with active reflink, effectively gaining root access. The exploit is noted for being silent, leaving no traces in kernel logs, and persisting across system reboots.

The discovery was facilitated by using Claude Mythos Preview to assist in manual audits, helping researchers isolate the race condition and generate a proof of concept.

Entities

Anthropic · Intel · Linus Torvalds · Linux kernel · Qualys