Skip to finding
important · Privilege — Linux/XFS

An XFS range-exchange flaw lets a local user rewrite readable root-owned files and become root.

Affects

The Linux kernel XFS filesystem when its experimental exchange_range feature is enabled.

The exploit requires the experimental exchange_range feature and abuses a cleared reflink flag so writes to a clone land on the privileged source file's shared blocks.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026