Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.

The company demonstrated the race

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

As of JDK 27, Oracle engineers will thus stop maintaining the macOS/x64 port

As of JDK 27, Oracle engineers will thus stop maintaining the macOS/x64 port Source: Hacker News

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow

More Tailscale tricks for your jailbroken Kindle

More Tailscale tricks for your jailbroken Kindle Source: Hacker News