Source: cockpit-files X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for cockpit-files. CVE-2026-91202[0]: | A flaw was found in cockpit-files. A low-privileged local user can | exploit this vulnerability by crafting a directory containing a | symbolic link (symlink) and then using the privileged "Paste as | owner" function. This allows for arbitrary file ownership changes | outside the intended pasted directory, leading to a compromise of | data integrity. In some cases, this could also lead to reduced | confidentiality if the new ownership grants unauthorized read | access. Exploitation requires user interaction to select a non- | original owner during the paste operation. https://bugzilla.redhat.com/show_bug.cgi?id=2465834 is currently the only reference, it's not clear whether this has been reported upstream yet. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-91202 https://www.cve.org/CVERecord?id=CVE-2026-91202 Please adjust the affected versions in the BTS as needed.

