Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

Read full story on The Hacker News
Share
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
AI disclosure

Summary

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The company demonstrated the race

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.