Source: cockpit-files X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for cockpit-files. CVE-2026-91205[0]: | A flaw was found in cockpit-files. A local unprivileged attacker can | exploit a race condition during directory creation with owner | assignment. By controlling a writable parent directory, the attacker | can replace a newly created directory with a symbolic link (symlink) | before the ownership change operation (chown) is applied. This | allows the attacker to redirect the ownership change to an arbitrary | file, potentially leading to information disclosure or unauthorized | modification of sensitive files. https://bugzilla.redhat.com/show_bug.cgi?id=2465834 is currently the only reference, it's not clear whether this has been reported upstream yet. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-91205 https://www.cve.org/CVERecord?id=CVE-2026-91205 Please adjust the affected versions in the BTS as needed.

