Hi, The following vulnerability was published for glibc. CVE-2026-86805[0]: | A time-of-check to time-of-use (TOCTOU) race condition in the | dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 | through 2.44 allows a local attacker to escalate privileges. When | expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) | programs, glibc validates the lexically normalized search path | against the trusted directories but then opens the raw, un- | normalized path. On systems where the Linux fs.protected_hardlinks | sysctl is disabled, a local attacker who hard-links such a program | into an attacker-controlled directory and wins a race to replace an | intermediate path component with a symbolic link can direct the | loader outside the trusted directory, causing it to load an | attacker-controlled shared object and execute arbitrary code with | the elevated privileges of the program. Exploitation requires an | installed setuid or setgid binary whose DT_RPATH uses $ORIGIN | followed by ".." traversal that normalizes into a trusted directory, | and the ability to hard-link that binary and win the race by | swapping a path component for a symbolic link. Major Linux-based OS | distributions ship with fs.protected_hardlinks enabled by default | and mitigate the vulnerability. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-86805 https://www.cve.org/CVERecord?id=CVE-2026-86805 [1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022 Please adjust the affected versions in the BTS as needed. Regards, Salvatore