CVE Tools

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

The Hacker NewsBy The Hacker News

ResearchLinux KernelRed Hat Enterprise Linux

Our summary

A long-standing Linux kernel vulnerability, tracked as CVE-2026-64600 and dubbed RefluXFS, has been disclosed. This flaw enables an unprivileged local user to overwrite root-owned files on XFS filesystems and achieve persistent root access. The issue affects default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux, among others. The vulnerability stems from a race condition in the XFS filesystem when reflink is enabled (reflink=1). A patch was merged into the Linux kernel on July 16, and updated kernels are now being distributed by major vendors. Exploitation requires specific conditions involving XFS configuration and file placement. While no active exploitation has been reported, systems meeting these criteria should apply updates immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store