Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

Summary

A newly disclosed Linux kernel flaw named RefluXFS (CVE-2026-64600) allows unprivileged local users to overwrite root-owned files on XFS filesystems, granting them persistent root access. This vulnerability affects default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux.

IFF Assessment

FOE

This vulnerability allows local users to gain root privileges, which is a significant security compromise for affected systems.

Severity

8.8 High (AI Estimated)

The CVSS score is estimated to be high due to the potential for local privilege escalation, allowing an attacker to gain administrative control of the system and potentially spread laterally. The attack vector is local, but the impact is high, enabling full system compromise.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability on systems running RHEL, Fedora Server, and Amazon Linux, especially those utilizing XFS filesystems. Local privilege escalation flaws are critical as they can be the first step in a more complex attack chain, allowing an attacker to establish persistence and pivot to other systems.

Read Full Story →