CircleCI Response to CVE-2026-64600 ("RefluXFS") Linux Kernel Vulnerability - Security - CircleCI Discuss
On July 22, 2026, Qualys disclosed CVE-2026-64600 (dubbed “RefluXFS”), a Linux kernel vulnerability in the XFS filesystem’s copy-on-write handling. RefluXFS is a race condition in how XFS handles concurrent direct I/O writes to a reflinked file. Exploiting this requires only an ordinary local user account with write access to a directory on an affected XFS volume. The vulnerability affects Linux kernels since v4.11 (2017) running XFS with reflink enabled. In response to the Qualys announcement,...