Back to all news
Security

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

The Hacker News·July 23, 2026·1 min read
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

A nine-year-old Linux kernel flaw, CVE-2026-64600, disclosed on July 22 lets unprivileged local users gain persistent root access on default Red Hat Enterprise Linux, Fedora Server, and Amazon Linux installs. Qualys demonstrated the race condition exploit targeting XFS filesystems. Patches are pending from affected distributions. The vulnerability affects millions of servers running default configurations.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store