Home / Jul 24, 2026 / Story
0
#3 The Hacker News general July 23, 2026 at 08:04 UTC

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

By [email protected] (The Hacker News)

AI Summary

Qualys disclosed RefluXFS (CVE-2026-64600), a nine-year-old race condition in the Linux kernel's XFS filesystem driver that allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are confirmed vulnerable, and Qualys demonstrated successful exploitation. Security teams running RHEL-derivative environments should prioritize patching immediately given the broad distribution footprint.

Relevance score: 85.0/100

# More from July 24