[Pkg-utopia-maintainers] Bug#1148476: cockpit-files: CVE-2026-91205
Moritz Mühlenhoff
jmm at inutil.org
Sat Sep 19 23:21:35 BST 2026
Source: cockpit-files
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security
Hi,
The following vulnerability was published for cockpit-files.
CVE-2026-91205[0]:
| A flaw was found in cockpit-files. A local unprivileged attacker can
| exploit a race condition during directory creation with owner
| assignment. By controlling a writable parent directory, the attacker
| can replace a newly created directory with a symbolic link (symlink)
| before the ownership change operation (chown) is applied. This
| allows the attacker to redirect the ownership change to an arbitrary
| file, potentially leading to information disclosure or unauthorized
| modification of sensitive files.
https://bugzilla.redhat.com/show_bug.cgi?id=2465834 is currently the
only reference, it's not clear whether this has been reported upstream yet.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-91205
https://www.cve.org/CVERecord?id=CVE-2026-91205
Please adjust the affected versions in the BTS as needed.
More information about the Pkg-utopia-maintainers
mailing list