Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86469

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

Отчет

Exploitation is local, requires write access to the destination directory, requires the uncommon temp-file fallback in handle_overwrite_open(), and requires winning a race. The usual g_file_replace() path writes to a temp file first and is not this bug. A successful race can overwrite or create a file the victim process is allowed to write.

Меры по смягчению последствий

Do not use g_file_replace(..., G_FILE_CREATE_REPLACE_DESTINATION) on paths in directories writable by less-privileged users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glib2Affected
Red Hat Enterprise Linux 10mingw-glib2Fix deferred
Red Hat Enterprise Linux 6glib2Fix deferred
Red Hat Enterprise Linux 7glib2Fix deferred
Red Hat Enterprise Linux 8glib2Fix deferred
Red Hat Enterprise Linux 8mingw-glib2Fix deferred
Red Hat Enterprise Linux 9glib2Affected
Red Hat Enterprise Linux 9mingw-glib2Fix deferred
Red Hat Hardened Imagesglib2Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2473839glib2: TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path

EPSS

Процентиль: 2%
0.00113
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 дней назад

(A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)

CVSS3: 5.3
nvd
9 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

CVSS3: 5.3
debian
9 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...

CVSS3: 5.3
github
8 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

EPSS

Процентиль: 2%
0.00113
Низкий

5.3 Medium

CVSS3