Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73584

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.3

Описание

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the /tmp directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

Отчет

This Moderate impact flaw in sblim-sfcb allows a local attacker to achieve privileged file corruption or denial of service through a time-of-check-to-time-of-use (TOCTOU) race condition. Exploitation requires a local low-privileged user to win a race during privileged sfcbrepos instance migration, which must be enabled and have specific repository content. The high attack complexity and specific preconditions limit its broader impact.

Меры по смягчению последствий

To mitigate this issue, if instance migration is not required, run the sfcbrepos command with the -i option to disable the vulnerable migration path. For example: sudo sfcbrepos -f -i. Alternatively, avoid running sfcbrepos with elevated privileges on systems where untrusted local users can concurrently write to the /tmp directory. A service restart or reload may be required for changes to take effect if sfcbrepos is managed by a service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sblim-sfcbFix deferred
Red Hat Enterprise Linux 6sblim-sfcbOut of support scope
Red Hat Enterprise Linux 7sblim-sfcbFix deferred
Red Hat Enterprise Linux 8sblim-sfcbFix deferred
Red Hat Enterprise Linux 9sblim-sfcbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=2462721sblim-sfcb: sblim-sfcb: Privileged file corruption and denial of service via insecure temporary file handling

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
15 дней назад

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

CVSS3: 6.3
nvd
15 дней назад

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

CVSS3: 6.3
github
15 дней назад

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

6.3 Medium

CVSS3