nygazet.com logo
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
technology

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

1 min read

CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterp... [6965 chars]

Read Original Article

Source: The Hacker News

Visit Source

Share this article