Bug#1147399: gvfs: CVE-2026-88924
Salvatore Bonaccorso
carnil at debian.org
Fri Sep 11 15:53:08 BST 2026
Source: gvfs
Version: 1.60.0-2
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/gvfs/-/issues/875
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: found -1 1.57.2-2+deb13u1
Hi,
The following vulnerability was published for gvfs.
CVE-2026-88924[0]:
| A flaw was found in the admin backend of gvfs. The privileged gvfsd-
| admin daemon changes the ownership of newly created private D-Bus
| sockets by calling the link-following chown() function on a pathname
| inside a user-controlled directory. A local attacker can exploit
| this via a Time-of-Check Time-of-Use (TOCTOU) race condition and
| exchange the socket pathname with a symbolic link pointing to an
| arbitrary root-owned file (such as /etc/pam.d/su). The daemon
| subsequently follows the symlink and changes the ownership of the
| targeted root-owned file to the attacker's user ID. This allows an
| authenticated local attacker to modify critical system files,
| leading to a full local privilege escalation to root.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-88924
https://www.cve.org/CVERecord?id=CVE-2026-88924
[1] https://gitlab.gnome.org/GNOME/gvfs/-/issues/875
[2] https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/352
Regards,
Salvatore
More information about the pkg-gnome-maintainers
mailing list