SECURITY·중요도 9·2026. 07. 23.·The Hacker News

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

── KO ──────────────────

RefluXFS 취약점이 RHEL 기본 설치에서 로컬 사용자에게 루트 접근을 허용합니다.

RefluXFS라는 새로운 리눅스 커널 취약점이 CVE-2026-64600으로 추적되며, 비특권 로컬 사용자가 XFS 파일 시스템에서 루트 소유 파일을 덮어쓰고 지속적인 루트 접근 권한을 얻게 합니다. Qualys는 기본적으로 설치된 레드햇 엔터프라이즈 리눅스(RHEL) 및 그 파생 제품들인 페도라 서버와 아마존 리눅스가 공격 조건을 충족할 수 있음을 나타냈습니다.


── EN ──────────────────

RefluXFS vulnerability allows local users root access on default RHEL installations.

The RefluXFS vulnerability, tracked as CVE-2026-64600, allows unprivileged local users to overwrite root-owned files on the XFS filesystem, gaining persistent root access. Qualys has indicated that default installations of Red Hat Enterprise Linux (RHEL) and its derivatives, including Fedora Server and Amazon Linux, can meet the conditions for exploitation.

원문 보기 →목록으로