CVE Tools
Back to feed
Research Linux Kernel privilege-escalation Red Hat Enterprise Linux Red Hat ai-ml

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

A long-standing Linux kernel vulnerability, tracked as CVE-2026-64600 and dubbed RefluXFS, has been disclosed. This flaw enables an unprivileged local user to overwrite root-owned files on XFS filesystems and achieve persistent root access. The issue affects default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux, among others. The vulnerability stems from a race condition in the XFS filesystem when reflink is enabled (reflink=1). A patch was merged into the Linux kernel on July 16, and updated kernels are now being distributed by major vendors. Exploitation requires specific conditions involving XFS configuration and file placement. While no active exploitation has been reported, systems meeting these criteria should apply updates immediately.