Article may be outdated

This article is 69 days old. Some details may have changed since publication.

Network World·3 min read·hard

Linux XFS has a decade-old race condition allowing full root access

S
Shweta Sharma
Linux XFS has a decade-old race condition allowing full root access
✦AI Summary

A decade-old race condition vulnerability in the Linux XFS filesystem, dubbed RefluXFS, allows unprivileged users to gain full root access. The flaw affects systems using the reflink feature and has been assigned a high severity score of 7.8.

Why it matters

This vulnerability poses a significant security risk to millions of enterprise Linux deployments, necessitating urgent patching to prevent unauthorized system access.

✦Dive DeeperCreate a free account to unlock

Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.

The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.

According to Qualys Threat Research Unit (TRU), there was a way around the file write protections reflink depends on. The bypass has existed in kernel versions since 2017 before a patch was made available last week.

“Using this vulnerability, a process running as an ordinary, unprivileged user can trigger the flaw and gain the ability to overwrite any readable file on an XFS volume at the block layer,” Saeed Abbasi, head of Qualys TRU, said in a blog post about the vulnerability, which he calls RefluXFS. “Exploitation is highly reliable and leaves no kernel log output.”

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in