RefluXFS (CVE-2026-64600), an XFS reflink direct-I/O race. A lock-drop window in the copy-on-write allocation path lets an unprivileged local user overwrite the on-disk contents of any file they can read (e.g.,/etc/passwd or a SUID-root binary) on any XFS with reflink=1 (the mkfs default since 2019, so the CloudLinux default). Result is full root.
CloudLinux 8, 9, and 10 are affected. The mitigation, patched kernel packages, and KernelCare live patch are currently in preparation. There is no fixed kernel to update to and no live patch in the feeds at this time.