selinux project selinux是selinux project团队开源的一个强制访问控制模块。 selinux project selinux 存在竞争条件问题漏洞,该漏洞源于policycoreutils中的fixfiles脚本存在TOCTOU竞争条件问题,本地攻击者可通过符号链接交换目录组件,利用文件发现与标签更改操作之间的竞态窗口,导致chcon修改任意系统文件的SELinux标签,从而破坏SELinux强制访问控制保护,影响关键文件如/etc/shadow。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | 3.11-2.2.hum1< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 3.11-2.2.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15816 | 7.5 HIGH | Dracut: dracut: root code execution via unescaped error message written to sourced emergen |
| CVE-2026-18938 | 6.2 MEDIUM | P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nes |
| CVE-2026-61477 | 2.3 LOW | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq confi |
No comments yet