公式動画ピックアップ
AAPL
ADBE
ADSK
AIG
AMGN
AMZN
BABA
BAC
BL
BOX
C
CHGG
CLDR
COKE
COUP
CRM
CROX
DDOG
DELL
DIS
DOCU
DOMO
ESTC
F
FIVN
GILD
GRUB
GS
GSK
H
HD
HON
HPE
HSBC
IBM
INST
INTC
INTU
IRBT
JCOM
JNJ
JPM
LLY
LMT
M
MA
MCD
MDB
MGM
MMM
MSFT
MSI
NCR
NEM
NEWR
NFLX
NKE
NOW
NTNX
NVDA
NYT
OKTA
ORCL
PD
PG
PLAN
PS
RHT
RNG
SAP
SBUX
SHOP
SMAR
SPLK
SQ
TDOC
TEAM
TSLA
TWOU
TWTR
TXN
UA
UAL
UL
UTX
V
VEEV
VZ
WDAY
WFC
WK
WMT
WORK
YELP
ZEN
ZM
ZS
ZUO
公式動画&関連する動画 [RefluXFS (CVE-2026-64600): Linux Kernel LPE to Root PoC on RHEL 10.2]
Qualys Threat Research Unit (TRU) demonstrates RefluXFS (CVE-2026-64600), a local privilege escalation in the Linux kernel XFS filesystem. An unprivileged local user escalates to root on a default RHEL 10.2 system by exploiting a race condition in the XFS copy-on-write (reflink) path.
The exploit overwrites a protected system file at the block layer, strips root's password protection, and returns passwordless root access within seconds. The change persists across reboots and leaves no kernel log output. Standard hardening, including SELinux in Enforcing mode, does not stop it.
CVE-2026-64600 affects any Linux distribution running an XFS root filesystem with reflink enabled, and has been present since kernel 4.11 (2017). This includes default installations of RHEL, CentOS Stream, Oracle Linux, Rocky, AlmaLinux, Amazon Linux, and Fedora Server.
What to do: apply your distribution's latest kernel security update and reboot to verify. There are no reliable temporary mitigations.
Read the full technical advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
Qualys Threat Research Unit: https://www.qualys.com/tru
#RefluXFS #CVE202664600 #LinuxKernel #PrivilegeEscalation #Qualys #VulnerabilityResearch #InfoSec #CyberSecurity
266
7