Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
A decade-old Linux kernel flaw known as RefluXFS allows local users to escalate privileges to root on default RHEL installations.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
📍 How it ended
The RefluXFS vulnerability was reported as a nine-year-old race condition in the Linux XFS filesystem. The flaw allowed local users and attackers to gain root access and privileges on default Red Hat Enterprise Linux installations.
Coverage of the issue quieted without a definitive conclusion regarding patches or resolution in the provided headlines.
Epilogue added 39d ago, after coverage quieted.
The brief
A critical security vulnerability identified as RefluXFS has emerged within the Linux kernel, specifically affecting the XFS file system. According to reports from Qualys and The Hacker News, this flaw enables local users to achieve a local privilege escalation to root access. The vulnerability is officially tracked as CVE-2026-64600. The issue is described as a race condition that has existed within the Linux XFS system for approximately nine to ten years, remaining undetected until now. The flaw specifically impacts default installations of Red Hat Enterprise Linux (RHEL), granting attackers full root privileges over the system. Coverage of the vulnerability is widespread across several technical and security news outlets.
Qualys provided the technical designation of the flaw as RefluXFS and identified it as a local privilege escalation. Tech Times reports that the vulnerability exposes 16 million RHEL systems to what it describes as a silent root takeover. Other outlets, including BleepingComputer, SecurityBrief Australia, and Network World, have emphasized the age of the flaw, noting that the race condition has persisted for a decade. These reports collectively highlight the severity of the risk for organizations relying on default RHEL configurations for their infrastructure. To understand the context of this trend, it is necessary to recognize the role of the XFS file system in Linux environments and the criticality of root access. Root privileges represent the highest level of administrative control on a Linux system, allowing a user to modify any file or configuration.
The fact that this race condition persisted for nine years indicates a long-term gap in the detection of this specific kernel flaw. Because the vulnerability exists in the kernel, it operates at a foundational level of the operating system, making it particularly dangerous for multi-user environments where local access can be leveraged to seize total control of the machine. Looking forward, the focus remains on the mitigation of CVE-2026-64600. Based on the reported facts, the immediate concern is for the 16 million RHEL systems identified by Tech Times as being exposed to this potential takeover. System administrators will need to monitor for updates to the Linux kernel that address the RefluXFS race condition. Coverage does not yet specify a patched version or a specific workaround, but the identification of the flaw by Qualys serves as the primary trigger for the current wave of security alerts and the need for urgent patching across affected Red Hat Enterprise Linux installations.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 52d ago.
Quick answers
What is the CVE identifier for the RefluXFS flaw?
The vulnerability is tracked as CVE-2026-64600.
Which specific Linux distribution is highlighted as being at risk?
Default installations of Red Hat Enterprise Linux (RHEL) are specifically mentioned as being vulnerable.
How many systems are reportedly exposed to this flaw?
According to Tech Times, 16 million RHEL systems are exposed to this vulnerability.
Coverage (6)
- New RefluXFS Linux flaw lets attackers gain root privileges BleepingComputer · 56d ago
- Linux kernel flaw lets local users gain root access SecurityBrief Australia · 56d ago
- Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover Tech Times · 56d ago
- Linux XFS has a decade-old race condition allowing full root access Network World · 56d ago
- RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) Qualys · 56d ago
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs The Hacker News · 56d ago
Topics
Related trends
CERN is moving more than 2,200 specialized computers from RHEL to Debian
CERN is migrating over 2,200 specialized accelerator control computers from Red Hat Enterprise Linux to Debian 13.
Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal
7 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Linux 7.1 Released: New NTFS Driver, Intel FRED For Panther Lake, Faster Arc Graphics
8 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.