CVE-2026-88924
Reported by redhat · Published September 10, 2026
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNOME | gvfs | 1.48.1, 1.48.1, 1.48.1 |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| GNOME | gvfs | 1.48.1, 1.48.1, 1.48.1 |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 6 |
Timeline
- Sep 10, 2026 CVE Published
- Sep 11, 2026 EPSS Score
- Sep 11, 2026 CVE Updated
- Sep 16, 2026 EPSS Score
References
- vdb-entryx_refsource_REDHAT
- RHBZ#2531456 issue-trackingx_refsource_REDHAT