<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Local-Exploit on CuraSec</title><link>https://curasec.metacog.co.kr/tags/local-exploit/</link><description>Recent content in Local-Exploit on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 12:47:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/local-exploit/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-64600: XFS race condition enables Linux local root escalation</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC on GitHub makes this LPE practically weaponizable on any Linux system using XFS (common on RHEL/CentOS derivatives); patch the kernel to the version fixing CVE-2026-64600 and prioritize systems where XFS is the root or primary filesystem.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Local privilege escalation via a kernel race condition offers a thin detection surface — no active campaign and no IOCs reported; note as a post-foothold escalation path attackers may chain after initial access, and revisit if exploit tooling appears in threat-actor toolkits.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-64600 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources&lt;/li>
&lt;/ul></description></item></channel></rss>