Saltar al contenido principal
Volver a noticias
vulnerabilities The Hacker News Verificada

Flaw de RefluXFS de 9 años en Linux permite a usuarios locales obtener acceso root en instalaciones predeterminadas de RHEL

linux vulnerabilidad seguridad root RHEL

Resumen

Un nuevo fallo de seguridad en el kernel de Linux, conocido como RefluXFS y registrado como CVE-2026-64600, permite a un usuario local no privilegiado sobrescribir archivos propiedad de root en un sistema de archivos XFS y obtener acceso root persistente. Esto afecta instalaciones predeterminadas de Red Hat Enterprise Linux y sus derivados. La explotación puede tener graves consecuencias de seguridad en sistemas vulnerables.

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The company demonstrated the race

CompartirXin

Noticias relacionadas