started · updated
Qualys AI uncovers critical Linux XFS bug affecting 16.4 million systems
Qualys' Threat Research Unit used Anthropic's Claude Mythos Preview model to locate a nine‑year‑old race condition in the XFS copy‑on‑write path of the Linux kernel (CVE‑2026‑64600, dubbed RefluXFS). The flaw allows an unprivileged user to overwrite any readable file on an XFS volume at the block layer, granting root privileges without leaving kernel logs. Saeed Abbasi of Qualys noted that the attack can strip the root password from /etc/passwd and persist across reboots.
The vulnerability bypasses common hardening mechanisms such as SELinux Enforcing, KASLR, SMEP, SMAP, seccomp, container isolation and kernel lockdown. Over 16.4 million systems are potentially exposed, including Red Hat Enterprise Linux 8‑10, CentOS Stream, Oracle Linux, Rocky Linux, AlmaLinux, Amazon Linux 2023+ and Fedora Server 31+. No runtime mitigation exists; remediation requires applying the vendor‑provided kernel patch and rebooting the affected machines.
Entities
Anthropic · CVE-2026-64600 · Linux kernel · Qualys · XFS filesystem