Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-25999

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-25999: yggdrasil-worker-package-manager security update (MODERATE)

[0.2.3-7]

  • Bump release for rebuild

[0.2.3-6]

  • Bump release for rebuild

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

yggdrasil-worker-package-manager

0.2.3-7.el10_2

Oracle Linux x86_64

yggdrasil-worker-package-manager

0.2.3-7.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 6.4
ubuntu
4 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
redhat
4 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
nvd
4 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

msrc
около 2 месяцев назад

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

CVSS3: 6.4
debian
4 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while ...