Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88924— Gvfs: gvfs-admin socket ownership race permits local root

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 gvfs 的管理后台中发现了一个缺陷。具有特权的 守护进程在用户可控目录内的路径名上调用跟随符号链接的 函数,以修改新创建的私有 D-Bus 套接字的属主。本地攻击者可以利用“检查时-使用时”(TOCTOU)竞态条件,将套接字的路径名替换为一个指向任意由 root 拥有的文件(例如 )的符号链接。随后,守护进程会跟随该符号链接,将目标 root 拥有文件的属主修改为攻击者的用户 ID。这使得经过身份验证的本地攻击者能够修改关键系统文件,从而实现完整的本地权限提升至 root。

CVSS 7.0 · High

Possible ATT&CK Techniques 1 AI

T1531.001
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gvfs: gvfs-admin socket ownership race permits local root
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-88924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88924

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88924 (2)

Other References for CVE-2026-88924 (1)

Same Patch Batch · Red Hat · 2026-09-10 · 8 CVEs total

CVE-2026-84042 7.8 HIGH Crun: crun: rootful krun with passt executes container payload as host root
CVE-2026-84828 6.5 MEDIUM Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
CVE-2026-88770 6.5 MEDIUM Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo
CVE-2026-88859 6.3 MEDIUM Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-
CVE-2026-88763 5.9 MEDIUM Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o
CVE-2026-88265 5.6 MEDIUM Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and
CVE-2026-88264 5.6 MEDIUM Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs

IV. Related Vulnerabilities

V. Comments for CVE-2026-88924

No comments yet


Leave a comment