Security · 4h ago
Nine-Year-Old Linux Flaw Grants Root Access on RHEL Systems
A Linux kernel vulnerability, CVE-2026-64600, allows unprivileged local users to overwrite root-owned files on XFS filesystems, gaining persistent root access. Qualys found that default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are exploitable. The flaw, disclosed July 22, has existed for nine years.
Meridian48 take
While the flaw requires local access, its presence in default enterprise Linux installations makes it a serious concern for system administrators.
Read the full reporting
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs →
The Hacker News
linux-kernelprivilege-escalation