vulnerability Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs A nine-year-old vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows unprivileged local users to gain root access on default Red Hat Enterprise Linux, CentOS Stream, and Amazon Linux installations. The flaw stems from a race condition during XFS reflink operations, where a cloned file can overwrit… The Hacker News · Jul 23, 2026 High CVE-2026-64600CVE-2026-8933linuxxfskernel