PT-2026-96830 · Gnu · Glibc
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.14 through 2.44
Description
A time-of-check to time-of-use (TOCTOU) race condition exists in the dynamic loader (ld.so). This occurs when expanding
$ORIGIN in DT RPATH for setuid/setgid (AT SECURE) programs; the system validates the lexically normalized search path against trusted directories but subsequently opens the raw, un-normalized path. On systems where the Linux fs.protected hardlinks sysctl is disabled, a local attacker can hard-link a program into a controlled directory and replace an intermediate path component with a symbolic link. This allows the loader to be directed outside the trusted directory to load an attacker-controlled shared object, leading to arbitrary code execution with elevated privileges. Exploitation requires a setuid or setgid binary whose DT RPATH uses $ORIGIN followed by ".." traversal that normalizes into a trusted directory.Recommendations
Update glibc to a version later than 2.44.
Enable the Linux
fs.protected hardlinks sysctl to mitigate the risk.Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glibc