HackerFeeds

CyberSecurity News

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

The Hacker News
· July 23, 2026

AI summary

A newly disclosed Linux kernel flaw, tracked as CVE-2026-64600, allows an unprivileged local user to overwrite root-owned files on an XFS filesystem and gain persistent root access. This vulnerability, known as RefluXFS, was disclosed on July 22. Qualys found that default installations of certain Linux distributions, including Red Hat Enterprise Linux and its derivatives, are vulnerable to exploitation. The flaw can be exploited by a local user to gain root access on affected systems, including Fedora Server and Amazon Linux. Qualys demonstrated a proof-of-concept exploit, showing the vulnerability can be used to elevate privileges. The vulnerability is approximately nine years old.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.