在 GLib2 中发现了一个漏洞。当 使用 标志时,如果创建 临时文件失败,该库会删除(unlink)目标文件并重新创建它,但此过程既未使用“独占创建”(exclusive creation),也未提供符号链接(symlink)保护。因此,能够写入目标目录的本地攻击者可以利用这一竞态条件(race condition),将写入操作重定向到另一个文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Hardened Images | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18922 | 9.8 CRITICAL | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo |
| CVE-2026-76578 | 9.8 CRITICAL | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi |
| CVE-2026-86404 | 8.8 HIGH | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging- |
| CVE-2026-19843 | 8.4 HIGH | 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console l |
| CVE-2026-79678 | 8.1 HIGH | Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm |
| CVE-2026-18453 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an |
| CVE-2026-18355 | 7.5 HIGH | 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound |
| CVE-2026-76560 | 7.5 HIGH | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt |
| CVE-2026-86332 | 6.5 MEDIUM | Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user |
No comments yet