#1148476 cockpit-files: CVE-2026-91205

Package:
src:cockpit-files
Source:
src:cockpit-files
Submitter:
Moritz Mühlenhoff
Date:
2026-09-20 05:35:02 UTC
Severity:
normal
Tags:
#1148476#5
Date:
2026-09-19 22:21:35 UTC
From:
To:
Hi,

The following vulnerability was published for cockpit-files.

CVE-2026-91205[0]:
| A flaw was found in cockpit-files. A local unprivileged attacker can
| exploit a race condition during directory creation with owner
| assignment. By controlling a writable parent directory, the attacker
| can replace a newly created directory with a symbolic link (symlink)
| before the ownership change operation (chown) is applied. This
| allows the attacker to redirect the ownership change to an arbitrary
| file, potentially leading to information disclosure or unauthorized
| modification of sensitive files.

https://bugzilla.redhat.com/show_bug.cgi?id=2465834 is currently the
only reference, it's not clear whether this has been reported upstream yet.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-91205
https://www.cve.org/CVERecord?id=CVE-2026-91205

Please adjust the affected versions in the BTS as needed.