Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
Overview
A newly disclosed vulnerability in the Linux kernel, known as RefluXFS and tracked as CVE-2026-64600, allows unprivileged local users to overwrite files owned by the root user on systems using the XFS filesystem. This flaw, which has been around for nine years, can grant persistent root access to attackers on default installations of Red Hat Enterprise Linux (RHEL), Fedora Server, and Amazon Linux. Researchers from Qualys demonstrated how this vulnerability can be exploited, raising significant concerns for system administrators and users of these platforms. Given the potential for local users to gain elevated privileges, it is crucial for affected organizations to assess their systems and apply necessary mitigations to prevent unauthorized access.
Key Takeaways
- Affected Systems: Red Hat Enterprise Linux (RHEL), Fedora Server, Amazon Linux, XFS filesystem
- Action Required: System administrators should apply available patches and updates for RHEL, Fedora Server, and Amazon Linux.
- Timeline: Disclosed on July 22, 2023
Original Article Summary
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The company demonstrated the race
Impact
Red Hat Enterprise Linux (RHEL), Fedora Server, Amazon Linux, XFS filesystem
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on July 22, 2023
Remediation
System administrators should apply available patches and updates for RHEL, Fedora Server, and Amazon Linux. Additionally, users should review their system configurations to limit local user access and monitor for unusual file changes.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, CVE, Vulnerability, and 2 more.