Volver a los avisos de seguridad

RefluXFS (CVE-2026-64600) Local Root Exploit: Release Status Tracker for CloudLinux

CloudLinux is affected by CVE-2026-64600. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle. CVSS base score: 7.8.

Critical 7.8 CVSS
CloudLinux CloudLinux 9 Ubuntu 22.04

Comandos de corrección

EL8+ (AlmaLinux/CloudLinux/Rocky)

sudo dnf update

Debian/Ubuntu

sudo apt update && sudo apt upgrade

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

RefluXFS (CVE-2026-64600) is a Linux kernel Local Privilege Escalation in the XFS filesystem, present in every kernel from v4.11 (April 2017) onward. On an affected host, an unprivileged local user can gain root, with no capabilities, namespaces, or special hardware required. It was discovered by Qualys and publicly…

RefluXFS (CVE-2026-64600) is a Linux kernel Local Privilege Escalation in the XFS filesystem, present in every kernel from v4.11 (April 2017) onward. On an affected host, an unprivileged local user can gain root, with no capabilities, namespaces, or special hardware required. It was discovered by Qualys and publicly disclosed on 2026-07-22 via oss-security.

This page is a running status tracker for RefluXFS across all CloudLinux delivery streams — a live snapshot of what is patched, what is pending, and how to install each fix. Snapshot: 2026-07-23.

Consolidated status matrix

CL Version Kernel Affected CL Kernel KernelCare Mitigation available
CL 3.10 ✅ not affected — (kernel too old to contain the bug) — —
CL7h 4.18 ❌ affected ✅ kernel-4.18.0-553.144.1.lve.el7h (rollout) ⏳ coming soon ✅ kernel update or KernelCare patch
CL8 4.18 ❌ affected ✅ kernel-4.18.0-553.144.1.lve.el8 (rollout) ✅ main feed ✅ kernel update or KernelCare patch
CL9 5.14 ❌ affected ✅ kernel-5.14.0-687.26.1.el9_8 (via AlmaLinux) — install → ✅ main feed ✅ kernel update or KernelCare patch
CL10 6.12 ❌ affected ✅ kernel-6.12.0-211.34.1.el10_2 (via AlmaLinux) — install → ✅ main feed ✅ kernel update or KernelCare patch
CL for Ubuntu 22.04 5.15 ✅ not affected (unless XFS with reflink is mounted) — (uses Ubuntu kernel) — —
CL8 LTS 4.18 / 5.14 (TuxCare ELS) ❌ affected ⏳ coming soon — ✅ kernel update or KernelCare patch
CL9 LTS 5.14 (TuxCare ELS) ❌ affected ⏳ coming soon — ✅ kernel update or KernelCare patch

Legend: ❌ affected · ✅ not affected / patched · ⏳ coming soon · ❓ unknown · — not applicable

Why This Matters on a Shared Host

The vulnerability creates a dangerous escalation path. On an unpatched host the chain is short, and none of it needs special access:

  1. Web-tier compromise. An attacker exploits a vulnerable plugin or outdated CMS, gaining access as an unprivileged process confined to a single site.
  2. RefluXFS exploitation. From that restricted process, the attacker leverages RefluXFS to become root without prior elevated privileges.
  3. Full server compromise. With root access, the attacker escapes all tenant boundaries and security limits, gaining access to every other tenant’s files, databases, credentials, and backups on that server.

On a patched host — or one running a KernelCare livepatch — step 2 fails: a web-tier compromise stays a web-tier compromise, one site to clean up rather than a whole server to rebuild. That is the practical difference the kernel fix delivers in multi-tenant hosting environments.

Installation instructions (CloudLinux)

CloudLinux 9 / 10 track AlmaLinux kernels directly — installing the AlmaLinux kernel is the CloudLinux install path.

CL9 + CL10 — AlmaLinux fixed kernels (published 2026-07-15→16)

Target versions: kernel-5.14.0-687.26.1.el9_8 (CL9) and kernel-6.12.0-211.34.1.el10_2 (CL10).

For CL10:

dnf update 'kernel*'
reboot

For CL9:

dnf update 'kernel*'
reboot

CL7h + CL8 — CloudLinux kernel rebuild (rollout repo)

Target versions: kernel-4.18.0-553.144.1.lve.el7h (CL7h) and kernel-4.18.0-553.144.1.lve.el8 (CL8). Both are available in the CloudLinux rollout repo. Once promoted to the stable channel, a plain yum update 'kernel*'; reboot is sufficient. CL7 is not affected (kernel too old to contain the bug).

CL8 LTS / CL9 LTS

Pending — see status matrix above.

Mitigation options

Mitigation for RefluXFS is one of two options: (1) update to the vendor-fixed kernel listed in the status matrix above and reboot; or (2) apply the KernelCare livepatch once available on your CloudLinux version — no reboot required. There is no reliable non-kernel workaround; targeting reflink, setuid bits, or filesystem layout does not close the primitive.

Comments

Leave a comment

Please log in to leave a comment. Published comments are visible to everyone.


Log in

Preguntas frecuentes

What is CVE-2026-64600?
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
Is CVE-2026-64600 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.47% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-64600?
Update CloudLinux to the patched release.Then confirm the running version matches the patched release listed above.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema