🟠 High  |  Source: The Hacker News


A nine-year-old Linux kernel vulnerability, CVE-2026-64600 (RefluXFS), allows an unprivileged local user to overwrite root-owned files on XFS filesystems and gain persistent root access. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are potentially exploitable. Discovered and demonstrated by Qualys, the flaw poses a serious privilege escalation risk on widely deployed enterprise and cloud Linux environments.

Security Architect’s Take: Prioritise patching RHEL, its derivatives, and Amazon Linux instances immediately, particularly any multi-tenant or shared environments where unprivileged local access exists — such as developer VMs, CI/CD build agents, or bastion hosts. In the interim, audit workloads using XFS filesystems and review whether untrusted local users have any interactive access to affected systems.

Original advisory: Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs