CVE-2026-64600 (RefluXFS) Vulnerability Assessment for CA API Gateway Appliance
search cancel

CVE-2026-64600 (RefluXFS) Vulnerability Assessment for CA API Gateway Appliance

book

Article ID: 451291

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

Security scanning tools (such as Wiz, Tenable, or Qualys) may flag the CA API Gateway appliance for CVE-2026-64600. This vulnerability, known as RefluXFS, is a local privilege escalation flaw in the Linux kernel related to a race condition in the XFS filesystem's reflink subsystem.

Environment

API Gateway Appliance (Debian)

Resolution

The CA API Gateway appliance is not affected by CVE-2026-64600. Customers may safely disposition this finding in their vulnerability management platforms as "Not Applicable" or "Risk Accepted" based on the absence of XFS filesystems.

Vulnerability Mechanism: The vulnerability requires the presence of an XFS filesystem with the "reflink" feature enabled to trigger the vulnerable code path in the Linux kernel.

Gateway Configuration: Running a "df -T" command will show that the API Gateway appliance does not use XFS filesystems.

Findings: Because the appliance does not utilize the XFS filesystem, the vulnerable subsystem is not in use. Therefore, the vulnerability cannot be exploited on the Gateway appliance.

 

Additional Information

Ongoing Maintenance & Patching

While this specific CVE is not applicable, Broadcom continues to provide general kernel security hardening:

  • Monthly Platform Packages (MPP): Security updates for the underlying Debian OS are bundled and released monthly as .L7P patches published on the Layer7 API Gateway - Solutions and Patches page.
  • Recommended Action: Customers should always apply the most recent MPP to ensure the appliance has the latest kernel security backports.