Kryptovaluta-ticker:
sysadmin fra Cyber Security News

RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access

Guru Baran
4 hours ago
6 Visninger
0 Kommentarer
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access

A new Linux vulnerability dubbed “RefluXFS” is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode. The vulnerability tracked as CVE-2026-64600 uncovered by Qualys Threat Research Unit (TRU) exploits a timing flaw triggered when two concurrent O_DIRECT writes target the same reflinked file on an XFS volume. XFS normally handles writes to shared blocks by allocating a new private block and remapping the file, but the kernel briefly drops its inode lock while waiting for transaction log space, creating a race window. A second writer can...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!