In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
[POC] CVE-2026-64600 — CVE-2026-64600
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
[POC] CVE-2026-64600 — CVE-2026-64600-RefluXFS
A Linux kernel local privilege escalation affecting the XFS filesystem copy-on-write (CoW) path.
[POC] CVE-2026-64600 — CVE-2026-64600-Refluxfs-PoC
A POC for the recently discovered Qualys bug on COW with XFS
[POC] CVE-2026-64600 — CVE-2026-64600-RefluXFS-PoC
PoC for RefluXFS
[POC] CVE-2026-64600 — VQ-RefluxCore
is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level race conditions and filesystem structure vulnerabilities (CVE-2026-64600 / RefluXFS)
[POC] CVE-2026-64600 — CVE-2026-64600
CVE-2026-64600 - Draft - Check todo
[POC] CVE-2026-64600 — CVE-2026-64600
CVE-2026-64600
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free