Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Yet Another Linux Kernel Vulnerability Discovered

Дата публикации: 27-07-2026 14:40:38

Affecting millions of systems, a kernel flaw discovered by Qualys could allow users to gain root privileges.

Основное содержимое страницы с новостью.

Affecting millions of systems, a kernel flaw discovered by Qualys could allow users to gain root privileges.

Here we go again: Another Linux kernel vulnerability has been discovered that could grant standard users root privileges. This time, the flaw could affect over 16 million systems. The vulnerability, CVE-2026-64600 (nicknamed RefluXFS), hits any system using the XFS filesystem.

The vulnerability was discovered by the Qualys Threat Research Unit as part of a research project using Anthropic's Claude Mythos Preview. Qualys first reported the vulnerability as "a race condition in the Linux kernel’s XFS filesystem copy-on-write path." The report goes on to say, "An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode."

As for how they discovered the flaw, Qualys said, "we tasked Claude Mythos Preview with hunting for a Dirty COW–style race condition in the Linux kernel, iteratively refining our prompts to narrow its focus toward race conditions in the core memory-management and filesystem directories." It took several iterations, but eventually "the model identified a race condition in the XFS filesystem and generated a functional proof-of-concept local privilege escalation."

The vulnerability has existed since kernel 4.11, and Qualys determined this was rated as an emergency priority because exploitation could happen using ordinary local privileges.

Immediate kernel patching is required to mitigate this threat. Kernels that include those patches are now available from vendors.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Another Logic Bug Found in Linux Kernel07.7401-06-2026
2New Vulnerability Discovered in Linux Kernel017.1717-07-2026
3New Linux Flaw Lets Attackers Escape VMs08.5713-07-2026
4432 отчёта об уязвимостях в ядре Linux. Локальная root-уязвимость Frag Gap013.8422-07-2026
5Seven iPhone models compromised by major security breach... is yours on the list?-3720-06-2026
6В древней Linux-утилите найдена критическая «дыра», которую не замечали 11 лет. Она открывает всем желающим root-доступ. Эксплойт умещается в одну строку-2823-01-2026
7PEdit-CoW и DirtyClone - уязвимости в ядре Linux, позволяющие получить root через изменение страничного кэша0826-06-2026
8Уязвимости в XFS, snapd и Exim, позволяющие поднять свои привилегии-18.7924-07-2026
9GhostLock, BadEpoll и Januscape - уязвимости в ядре Linux, позволяющие получить права root и обойти изоляцию KVM0811-07-2026
10KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"-2702-07-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.34. Источник: www.linux-magazine.com.