在 gvfs 的管理后台中发现了一个缺陷。具有特权的 守护进程在用户可控目录内的路径名上调用跟随符号链接的 函数,以修改新创建的私有 D-Bus 套接字的属主。本地攻击者可以利用“检查时-使用时”(TOCTOU)竞态条件,将套接字的路径名替换为一个指向任意由 root 拥有的文件(例如 )的符号链接。随后,守护进程会跟随该符号链接,将目标 root 拥有文件的属主修改为攻击者的用户 ID。这使得经过身份验证的本地攻击者能够修改关键系统文件,从而实现完整的本地权限提升至 root。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84042 | 7.8 HIGH | Crun: crun: rootful krun with passt executes container payload as host root |
| CVE-2026-84828 | 6.5 MEDIUM | Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token |
| CVE-2026-88770 | 6.5 MEDIUM | Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo |
| CVE-2026-88859 | 6.3 MEDIUM | Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script- |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88265 | 5.6 MEDIUM | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and |
| CVE-2026-88264 | 5.6 MEDIUM | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs |
No comments yet