Over 16.4 Million Computers in Danger Worldwide Due to Security Flaw

Cybersecurity company Qualys has disclosed a critical Linux vulnerability that could allow someone with a normal local user account to gain full control of an affected system.

The flaw, tracked as CVE-2026-64600 and named RefluXFS, could affect more than 16.4 million systems worldwide.

It was discovered by the Qualys Threat Research Unit during research that also used Anthropic’s Claude Mythos Preview to help with the analysis.

What is RefluXFS?

RefluXFS affects the Linux kernel, the core part of the operating system that manages hardware, memory, files, and other important system functions.

Qualys says the problem is a race condition in the XFS filesystem.

A race condition happens when two operations occur at nearly the same time, and the system handles them in an unsafe order. Attackers can sometimes take advantage of that timing problem to make the system do something it normally would not allow.

The flaw affects the copy-on-write system used by XFS. Copy-on-write is a method that avoids immediately duplicating data when a copy is created. Instead, the system shares the existing data until one copy needs to be changed.

ALSO READ
These Xiaomi Phones Will No Longer Get Software Support

Vulnerability Dates Back to 2017

Qualys says the flaw has existed since Linux kernel version 4.11, which was released in 2017.

It could affect more than 16.4 million systems, including machines running:

  • Red Hat Enterprise Linux
  • Oracle Linux
  • Amazon Linux
  • Fedora

The vulnerability affects XFS volumes that use reflinks.

Reflinks allow files to share the same underlying data without creating full copies, which saves storage space until one of the files is changed.

Attackers Could Gain Root Access

Qualys says an attacker who already has access to a normal local user account could exploit the vulnerability to overwrite protected files.

This could allow the attacker to gain root privileges.

Root is the highest level of access on a Linux system. A root user can change protected files, install software, modify system settings, and control almost every part of the machine.

This means an attacker would not need to start with administrator-level access. A standard local account could potentially be enough to begin the attack.

Changes Can Survive a Reboot

Qualys says successful exploitation can modify protected files without creating entries in the kernel logs. That could make the attack harder to notice. The changes made to files can also remain after the computer or server is restarted.

Qualys considers RefluXFS an emergency-priority vulnerability because it can start from ordinary local privileges and end with full root access. The company also says the exploit works even when common Linux security protections are enabled.

AI Helped Researchers Find the Flaw

Qualys discovered the vulnerability during a research project that used Anthropic’s Claude Mythos Preview alongside human researchers.

Saeed Abbasi, head of the Qualys Threat Research Unit, said AI was used to speed up the manual auditing process, but humans remained responsible for checking and confirming the results.

He said the vulnerability went through the same evidence and responsible-disclosure standards Qualys uses for its other security findings.

Update Immediately

Qualys recommends that organisations install kernel updates provided by their Linux vendors as soon as possible.

After installing the update, affected systems should be rebooted so the fixed kernel can take effect. The company recommends giving priority to internet-facing systems and multi-tenant environments.

Internet-facing systems are servers or computers that can be reached directly from the internet. Multi-tenant environments are systems where several customers or users share the same underlying infrastructure, such as some cloud platforms.

Qualys says fixed kernels are already available from vendors. However, there are currently no practical temporary fixes or configuration changes that can fully protect affected systems without installing the security update.

Stay Connected with ProPakistani

Get the latest tech news, telecom insights, and product launches wherever you prefer.

Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.



Get Alerts

ProPakistani Community

Join the groups below to get the latest news and updates.



>