PT-2026-56478 · Rocky Linux · Rocky Linux

·

CVE-2026-39822

·

Published

2026-07-07

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description On Unix systems, opening a file in an os.Root improperly follows symbolic links to locations outside of the Root. This occurs when the final path component of a path is a symbolic link and the path ends in a forward slash (/). For instance, calling root.Open("symlink/") allows access to the target of the symbolic link even if it points outside the designated root directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:37435
ALSA-2026:37436
ALSA-2026:38493
ALSA-2026:38494
ALSA-2026:38495
ALSA-2026:38878
ALSA-2026:38995
AZL-92303
AZL-92309
BIT-GOLANG-2026-39822
CLEANSTART-2026-AC51978
CLEANSTART-2026-BI19096
CLEANSTART-2026-CR75797
CLEANSTART-2026-FD44150
CLEANSTART-2026-GX27419
CLEANSTART-2026-GY91527
CLEANSTART-2026-HP74907
CLEANSTART-2026-JT42679
CLEANSTART-2026-KB08955
CLEANSTART-2026-KL21881
CLEANSTART-2026-KS96802
CLEANSTART-2026-LD38774
CLEANSTART-2026-LZ81863
CLEANSTART-2026-MA24172
CLEANSTART-2026-MZ40522
CLEANSTART-2026-PH23874
CLEANSTART-2026-PK07483
CLEANSTART-2026-PY84482
CLEANSTART-2026-RT37134
CLEANSTART-2026-RV11606
CLEANSTART-2026-SO86245
CLEANSTART-2026-SP73148
CLEANSTART-2026-TJ75897
CLEANSTART-2026-UM67329
CLEANSTART-2026-VA62549
CLEANSTART-2026-VU72808
CLEANSTART-2026-VY16523
CLEANSTART-2026-WQ12431
CLEANSTART-2026-WT22902
CLEANSTART-2026-YT82900
CLEANSTART-2026-ZA15834
CLEANSTART-2026-ZY59905
CVE-2026-39822
GO-2026-4970
OPENSUSE-SU-2026:11212-1
OPENSUSE-SU-2026:11232-1
OPENSUSE-SU-2026:11393-1
OPENSUSE-SU-2026:21319-1
OPENSUSE-SU-2026:21321-1
OPENSUSE-SU-2026:21324-1
OPENSUSE-SU-2026:21341-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:36477
RHSA-2026:36510
RHSA-2026:37435
RHSA-2026:37436
RHSA-2026:38493
RHSA-2026:38494
RHSA-2026:38495
RHSA-2026:38878
RHSA-2026:38995
RHSA-2026:49702
RHSA-2026:49712
SUSE-SU-2026:22638-1
SUSE-SU-2026:22641-1
SUSE-SU-2026:22643-1
SUSE-SU-2026:22656-1
SUSE-SU-2026:2817-1
SUSE-SU-2026:2818-1
SUSE-SU-2026:3046-1
SUSE-SU-2026:3047-1
SUSE-SU-2026:3102-1
SUSE-SU-2026:3151-1

Affected Products

Rocky Linux