Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59676

Опубликовано: 23 июл. 2026
Источник: debian
EPSS Низкий

Описание

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
policycoreutilsfixed2.7-1package
selinux-pythonfixed3.7-1package
selinux-pythonnot-affectedbookwormpackage
selinux-pythonnot-affectedbullseyepackage

Примечания

  • src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building

  • policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a

  • separate upstream package.

  • https://security.opensuse.org/2026/07/15/selinux-seunshare.html

EPSS

Процентиль: 0%
0.00087
Низкий

Связанные уязвимости

ubuntu
10 дней назад

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

CVSS3: 5.3
redhat
10 дней назад

A flaw was found in policycoreutils through 3.10 in seunshare. A TOCTOU race lets a local user running in an unconfined SELinux domain delete arbitrary root-owned files. Removing critical system files can cause denial of service; integrity impact is limited to unauthorized deletion.

nvd
10 дней назад

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

msrc
9 дней назад

Local File Deletion Attack Vector in rm_rf() in seunshare

github
10 дней назад

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

EPSS

Процентиль: 0%
0.00087
Низкий