Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
COWSlip — xfs kernel LPE (CVE-2026-64600), disclosed by Qualys on 22 July 2026 | Kitploit
Tools/GitHubGitHub/k4ntux/cowslip
Privilege EscalationVulnerability AnalysisExploitationBinary Exploitation
GitHubk4ntux/cowslip

COWSlip

xfs kernel LPE (CVE-2026-64600), disclosed by Qualys on 22 July 2026

View Repository
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

COWSlip: XFS reflink stale-mapping LPE

(originally RefluXFS or CVE-2026-64600)

logo

The name describes the mechanism:

  • COW identifies XFS copy-on-write/reflink handling.
  • Slip describes the stale data-fork mapping slipping to the wrong physical block after the ILOCK cycle.

However, official credits belong to Qualys and their RefluXFS (CVE-2026-64600), disclosed via oss-security. COWSlip was crafted independently from the patch landed in xfs for-next branch. Qualys' RefluXFS was found a week earlier and was fixed as a null-day.

COWSlip is a one-day PoC based on the XFS fix shipped in Red Hat advisory RHBA-2026:39332, which was marked [Exploits (KEV)] (initially).

After inspecting kernel.spec and the SRPM diff, the corresponding patch was found in the XFS Linux for-next branch:

xfs: resample the data fork mapping after cycling ILOCK

The timing was notable: the fix appeared in an enterprise kernel update shortly after the corresponding change landed in the development branch. In short, the patch fixes a local privilege-escalation primitive in XFS. Exploitability depends on the filesystem layout and setuid configuration; it is especially relevant to RHEL-family installations that use XFS for the root filesystem.

Reproduction

PoC targets a pre-fix XFS kernel with reflink enabled, an existing root-owned setuid ELF target (/usr/bin/su by default), and a user-writable clone directory on the same XFS filesystem. By default, the target is /usr/bin/su and the clone directory is /tmp/cowslip-clones, so /tmp must be on that XFS filesystem. It races aligned direct-I/O CoW writes against reflink clones, replaces the target's ELF interpreter path in the raced first block, and starts /bin/bash -p when the setuid target executes the loader.

Build:

root@kitploit:~
gcc -O2 -Wall -Wextra -pthread poc.c -o /tmp/cowslip
gcc -nostdlib -static-pie -s -Wl,-e,_start -o /tmp/cowslip-loader loader.S

The static-PIE loader is required for the older EL8 kernel path; the former ET_EXEC loader can segfault before starting the shell.

Run as an unprivileged user with the target and clone directory on the same reflink-enabled XFS filesystem:

root@kitploit:~
/tmp/cowslip

Optional controls are POC_TARGET, POC_TRIES, and POC_THREADS:

root@kitploit:~
POC_TARGET=/usr/bin/su POC_TRIES=20000 POC_THREADS=32 /tmp/cowslip

The PoC intentionally does not restore the target after a hit. From a normal root login, reinstall the owning package and verify it:

root@kitploit:~
dnf -y reinstall util-linux || yum -y reinstall util-linux
rpm -V util-linux

An empty rpm -V result indicates that the package files match the installed package database.

Tested kernels:

  • 6.12.0-211.33.1.el10_2: hit
  • 5.14.0-687.25.1.el9_8: hit
  • 5.14.0-687.26.1.el9_8: no hit; this kernel contains the XFS fix
  • 4.18.0-553.143.1.el8_10: hit
  • 4.18.0-553.144.1.el8_10: no hit; this kernel contains the XFS fix

Fix: xfs: resample the data fork mapping after cycling ILOCK

Introduced by 3c68d44a2b49a0 in v4.11; affected until the resampling fix is applied.

The trigger requires a reflink-enabled XFS filesystem, a root-owned setuid ELF target on that filesystem, and a directory on the same filesystem that is writable by the unprivileged user.

Download Tool