Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.

The company demonstrated the race

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Park by Robot at London Gatwick Airport

Park by Robot at London Gatwick Airport Source: Hacker News

Sixty percent of US consumers say ‘AI’ in brand messaging is a turnoff

Sixty percent of US consumers say ‘AI’ in brand messaging is a turnoff Source: Hacker News

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos looked at a week of its own endpoint data and found that AI coding agents such as