RefluXFS Linux flaw can give local users root on default Red Hat Enterprise Linux systems

A newly publicized Linux vulnerability can let a normal user take full control of affected Red Hat Enterprise Linux systems. The flaw, dubbed RefluXFS, is described as a nine-year-old local privilege-escalation issue affecting default RHEL installations through the XFS file system; the article indicates local access is required and the impact is root-level compromise. The provided text does not include a CVE ID or patch details.
Why it matters: Organizations running RHEL should treat this as a high-priority hardening and patching issue because a low-privilege user or intruder who already has a foothold could turn that access into full system control. Admins should identify affected RHEL systems and review vendor guidance or updates immediately.

Sources

New RefluXFS Linux flaw lets attackers gain root privileges
Sergiu Gatlan 2026.07.23 97% relevant
This article reports the same underlying event: Qualys' disclosure of the RefluXFS Linux kernel XFS race-condition flaw, tracked as CVE-2026-64600, that can let local attackers overwrite protected files and gain root. It adds patch timing details, affected distributions including RHEL, Oracle Linux, Amazon Linux, Fedora, Rocky Linux, AlmaLinux, and CloudLinux, and notes that standard hardening defenses do not stop exploitation.
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
info@thehackernews.com (The Hacker News) 2026.07.23 100% relevant
This appears to establish a distinct new vulnerability story about the RefluXFS local root flaw on default RHEL installs, and it does not match any listed existing tracked story.
← Back to all stories