Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-41259

Опубликовано: 03 июн. 2026
Источник: debian

Описание

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
swupdatefixed2026.05+dfsg-1package
swupdateno-dsatrixiepackage
swupdateno-dsabookwormpackage
swupdatepostponedbullseyepackage

Примечания

  • Fixed by: https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d (2026.05)

Связанные уязвимости

ubuntu
3 месяца назад

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.

nvd
3 месяца назад

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.

github
3 месяца назад

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.