PT-2026-95635 · Unknown · Cockpit-Files
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cockpit-files (affected versions not specified)
Description
A timing issue, known as a symlink race condition, exists during privileged file operations such as changing file ownership or permissions. A local attacker can manipulate directory entries to redirect these operations to unintended files. This may result in unauthorized changes to file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable. A symlink race condition occurs when a program checks a file's properties and then performs an action on it, but an attacker replaces the file with a symbolic link to another file in the brief interval between the check and the action.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cockpit-Files