As cited
Copy frozen at (site build).
vulnerabilities
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
A nine-year-old flaw in the Linux kernel's XFS filesystem implementation, disclosed on July 22, 2026 as CVE-2026-64600, allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default configurations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are vulnerable to the issue. Qualys has demonstrated a working exploitation method for the race condition.
Why it matters: Linux administrators running default RHEL, Fedora Server, or Amazon Linux deployments with XFS filesystems and untrusted local users face immediate privilege escalation risk; patching or configuration changes are needed to prevent local accounts from obtaining root access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
A nine-year-old flaw in the Linux kernel's XFS filesystem implementation, disclosed on July 22, 2026 as CVE-2026-64600, allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default configurations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are vulnerable to the issue. Qualys has demonstrated a working exploitation method for the race condition.
Why it matters: Linux administrators running default RHEL, Fedora Server, or Amazon Linux deployments with XFS filesystems and untrusted local users face immediate privilege escalation risk; patching or configuration changes are needed to prevent local accounts from obtaining root access.
- Source published
- First seen by Cybersecurity Tracker