Source: glibc
Version: 2.43-5
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc.

CVE-2026-86805[0]:
| A time-of-check to time-of-use (TOCTOU) race condition in the
| dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14
| through 2.44 allows a local attacker to escalate privileges. When
| expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE)
| programs, glibc validates the lexically normalized search path
| against the trusted directories but then opens the raw, un-
| normalized path. On systems where the Linux fs.protected_hardlinks
| sysctl is disabled, a local attacker who hard-links such a program
| into an attacker-controlled directory and wins a race to replace an
| intermediate path component with a symbolic link can direct the
| loader outside the trusted directory, causing it to load an
| attacker-controlled shared object and execute arbitrary code with
| the elevated privileges of the program.  Exploitation requires an
| installed setuid or setgid binary whose DT_RPATH uses $ORIGIN
| followed by ".." traversal that normalizes into a trusted directory,
| and the ability to hard-link that binary and win the race by
| swapping a path component for a symbolic link. Major Linux-based OS
| distributions ship with fs.protected_hardlinks enabled by default
| and mitigate the vulnerability.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86805
    https://www.cve.org/CVERecord?id=CVE-2026-86805
[1] 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to