Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6842

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the ~/.local directory. This allows the attacker to inject a malicious .desktop launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.

Отчет

This is a Low impact flaw where nano creates the ~/.local directory with insecure permissions (0777) in permissive umask environments. A local attacker can exploit this to inject a malicious .desktop launcher. This issue affects Red Hat Enterprise Linux 8 and 9.

Меры по смягчению последствий

Ensure that the system's umask is configured to a secure value, such as 0022 or 0077, to prevent the creation of world-writable directories. This can be set system-wide in /etc/profile or /etc/bashrc, or for individual users in their ~/.bashrc or ~/.profile. A secure umask will ensure that newly created directories, including ~/.local by nano, have appropriate permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nanoFix deferred
Red Hat Enterprise Linux 6nanoFix deferred
Red Hat Enterprise Linux 7nanoFix deferred
Red Hat Enterprise Linux 8nanoFix deferred
Red Hat Enterprise Linux 9nanoFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2460018nano: nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions

EPSS

Процентиль: 0%
0.00085
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
3 месяца назад

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.

CVSS3: 2.5
nvd
3 месяца назад

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.

CVSS3: 2.5
msrc
3 месяца назад

Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions

CVSS3: 2.5
debian
3 месяца назад

A flaw was found in nano. In environments with permissive umask settin ...

CVSS3: 2.5
github
3 месяца назад

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.

EPSS

Процентиль: 0%
0.00085
Низкий

2.5 Low

CVSS3