#3
The Hacker News
general
July 23, 2026 at 08:04 UTC
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
By [email protected] (The Hacker News)
AI Summary
Qualys disclosed RefluXFS (CVE-2026-64600), a nine-year-old race condition in the Linux kernel's XFS filesystem driver that allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are confirmed vulnerable, and Qualys demonstrated successful exploitation. Security teams running RHEL-derivative environments should prioritize patching immediately given the broad distribution footprint.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →