256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs - The Hacker News

Share
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs - The Hacker News
Image · Internet

What the report says

The Hacker News reported that a Linux kernel flaw dubbed RefluXFS, tracked as CVE-2026-64600, can allow an unprivileged local user to overwrite files owned by root on some XFS filesystems and obtain persistent root access. The vulnerability was disclosed on July 22, 2026, and Qualys said it affects systems running Linux 4.11 or later when XFS was created with reflink support enabled and a readable target file shares the same filesystem with a directory writable by the attacker.

According to the report, default installations that may meet those conditions include Red Hat Enterprise Linux 8, 9 and 10 and derivatives, Fedora Server 31 and later, Amazon Linux 2023, and Amazon Linux 2 images from December 2022 onward. RHEL 7 is not affected because it predates XFS reflink support. Debian, Ubuntu, SLES and openSUSE are generally exposed only where administrators selected reflink-enabled XFS, rather than default root filesystem choices.

Qualys said the bug lies in an XFS reflink race involving stale block mappings during copy-on-write handling. Its researchers demonstrated attacks against files such as /etc/passwd and setuid-root binaries, with writes landing at the block layer while ownership, permissions, timestamps and setuid bits remained unchanged. The article said Qualys used Anthropic’s Claude Mythos Preview model to help identify the flaw, then researchers reproduced and validated it before coordinated disclosure.

A fix was merged upstream on July 16, and Linux vendors have begun issuing backported kernel updates. Red Hat rated its advisories Important for affected RHEL streams. Qualys said there is no practical temporary mitigation once a filesystem is created with reflinks, and The Hacker News reported no known in-the-wild exploitation at publication. Administrators are advised to install vendor kernel updates, reboot, and verify the fixed kernel is running.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting