Home / Jul 25, 2026 / Story
0
#9 BleepingComputer general July 23, 2026 at 11:40 UTC

New RefluXFS Linux flaw lets attackers gain root privileges

By Sergiu Gatlan

AI Summary

A nine-year-old race condition in the Linux kernel's XFS filesystem driver, tracked as CVE-2026-64600 and dubbed 'RefluXFS,' allows local attackers to overwrite protected files and escalate privileges to root. The vulnerability has existed since at least 2017, affecting a wide range of Linux distributions that use XFS as their default filesystem, including RHEL, CentOS, and Fedora variants. Local privilege escalation flaws in widely deployed Linux kernel filesystems present significant risk in shared hosting, container, and cloud environments.

Relevance score: 74.0/100

# More from July 25