Live Feed

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs - The Hacker News

Reported by The Hacker News | July 23, 2026, 8:04 am

Article Image

CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.

Want to read the full report?

You are viewing a syndication snippet provided by the publisher via NewsAPI.

Read Full Story on Publisher Site ↗