We are running Rocky Linux 9.8 and would like to know whether a patched kernel addressing CVE-2026-64600, also known as RefluXFS, will be made available.
Our systems use XFS, so we would appreciate clarification on the following points:
Has the fix already been backported to a Rocky Linux 9.8 kernel package?
Will the fixed kernel be published through the standard Rocky Linux security repositories, such as BaseOS or an update repository?
Is there a specific kernel package version that includes the fix?
Is there an estimated release date for the patched package?
Are there any recommended mitigations until the updated kernel is available?
Red Hat describes this vulnerability in: cve-details
That includes mitigations.
As said above, that page does now list the status of RHEL 9 as Fixed and points to the https://access.redhat.com/errata/RHBA-2026:39332
The fixed RHEL 9 kernel has version 5.14.0-687.26.1.el9_8
Rocky mirror near me has two more recent kernels:
Version Date
5.14.0-687.26.1.el9_8 2026-07-15
5.14.0-687.29.1.el9_8 2026-07-22
Based on the current Rocky Linux and Red Hat advisories, the fix for CVE-2026-64600 (RefluXFS) has already been backported into the kernel-5.14.0-687.26.1.el9_8 series for Rocky Linux 9.8. The update is distributed through the normal Rocky Linux update channels rather than requiring a separate patch.