PT-2026-96830 · Gnu · Glibc

·

CVE-2026-86805

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions glibc versions 2.14 through 2.44
Description A time-of-check to time-of-use (TOCTOU) race condition exists in the dynamic loader (ld.so). This occurs when expanding $ORIGIN in DT RPATH for setuid/setgid (AT SECURE) programs; the system validates the lexically normalized search path against trusted directories but subsequently opens the raw, un-normalized path. On systems where the Linux fs.protected hardlinks sysctl is disabled, a local attacker can hard-link a program into a controlled directory and replace an intermediate path component with a symbolic link. This allows the loader to be directed outside the trusted directory to load an attacker-controlled shared object, leading to arbitrary code execution with elevated privileges. Exploitation requires a setuid or setgid binary whose DT RPATH uses $ORIGIN followed by ".." traversal that normalizes into a trusted directory.
Recommendations Update glibc to a version later than 2.44. Enable the Linux fs.protected hardlinks sysctl to mitigate the risk.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86805

Affected Products

Glibc