logo

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

ID: 317269ee-b960-58e8-afdc-7682f924d5ef

STIX ID: report--317269ee-b960-58e8-afdc-7682f924d5ef

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

**RefluXFS (CVE-2026-64600)** is a Linux kernel XFS reflink copy-on-write race that allows an unprivileged local user to overwrite root-owned files and gain persistent root access when an XFS filesystem was created with reflink=1 and the target and attacker-writable directory share the same filesystem; major distributions (RHEL, Fedora Server, Amazon Linux and derivatives) can meet these conditions by default. The vulnerability stems from a stale block mapping across a lock cycle in XFS reflink handling; a patch was merged and vendors are shipping backported kernels, so administrators should apply updates and reboot since the running kernel remains vulnerable until restarted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.