Home/News/Nine-Year-Old Linux Flaw Grants Root Access on RHEL
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Nine-Year-Old Linux Flaw Grants Root Access on RHEL

Nine-Year-Old Linux Flaw Grants Root Access on RHEL

A critical Linux kernel flaw, named RefluXFS and disclosed on July 22, 2026, has been identified as CVE-2026-64600. This vulnerability allows an unprivileged local user to overwrite root-owned files on an XFS filesystem, thereby enabling them to achieve persistent root access. Qualys, the security firm that disclosed the flaw, stated that default installations of Red Hat Enterprise Linux (RHEL) and its derivatives, including Fedora Server and Amazon Linux, are susceptible to exploitation.

The RefluXFS flaw has reportedly existed for nine years, highlighting a significant oversight in kernel security over an extended period. The vulnerability is a race condition that can be triggered by a local user. Qualys successfully demonstrated the exploit, confirming its viability on affected systems. The implications of this flaw are severe, as it bypasses standard user privilege limitations and grants attackers complete control over compromised systems.

Exploitation of RefluXFS could lead to widespread security breaches across numerous servers running vulnerable Linux distributions. Attackers could use this access to install malware, steal sensitive data, disrupt services, or use the compromised systems as a pivot point for further network attacks. The long-standing nature of the vulnerability suggests that many systems may have been unknowingly exposed for years.

Qualys has provided details on the conditions required for exploitation, emphasizing the race condition aspect. The disclosure of CVE-2026-64600 prompts an urgent need for system administrators to patch their RHEL, Fedora Server, and Amazon Linux installations. The company's demonstration underscores the practical threat posed by this long-dormant vulnerability, which could have already been leveraged by malicious actors.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next