Security scanning tools (such as Wiz, Tenable, or Qualys) may flag the CA API Gateway appliance for CVE-2026-64600. This vulnerability, known as RefluXFS, is a local privilege escalation flaw in the Linux kernel related to a race condition in the XFS filesystem's reflink subsystem.
API Gateway Appliance (Debian)
The CA API Gateway appliance is not affected by CVE-2026-64600. Customers may safely disposition this finding in their vulnerability management platforms as "Not Applicable" or "Risk Accepted" based on the absence of XFS filesystems.
Vulnerability Mechanism: The vulnerability requires the presence of an XFS filesystem with the "reflink" feature enabled to trigger the vulnerable code path in the Linux kernel.
Gateway Configuration: Running a "df -T" command will show that the API Gateway appliance does not use XFS filesystems.
Findings: Because the appliance does not utilize the XFS filesystem, the vulnerable subsystem is not in use. Therefore, the vulnerability cannot be exploited on the Gateway appliance.
While this specific CVE is not applicable, Broadcom continues to provide general kernel security hardening:
.L7P patches published on the Layer7 API Gateway - Solutions and Patches page.