important · Privilege — Linux/XFS
An XFS range-exchange flaw lets a local user rewrite readable root-owned files and become root.
Affects
The Linux kernel XFS filesystem when its experimental exchange_range feature is enabled.
The exploit requires the experimental exchange_range feature and abuses a cleared reflink flag so writes to a clone land on the privileged source file's shared blocks.
Detail and 2 sources
The completed chain overwrites /etc/passwd, and upstream identifies fixed stable releases.