#1148727 glibc: CVE-2026-86805

Package:
src:glibc
Source:
src:glibc
Submitter:
Salvatore Bonaccorso
Date:
2026-09-22 18:33:02 UTC
Severity:
normal
Tags:
#1148727#5
Date:
2026-09-22 18:30:09 UTC
From:
To:
Hi,

The following vulnerability was published for glibc.

CVE-2026-86805[0]:
| A time-of-check to time-of-use (TOCTOU) race condition in the
| dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14
| through 2.44 allows a local attacker to escalate privileges. When
| expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE)
| programs, glibc validates the lexically normalized search path
| against the trusted directories but then opens the raw, un-
| normalized path. On systems where the Linux fs.protected_hardlinks
| sysctl is disabled, a local attacker who hard-links such a program
| into an attacker-controlled directory and wins a race to replace an
| intermediate path component with a symbolic link can direct the
| loader outside the trusted directory, causing it to load an
| attacker-controlled shared object and execute arbitrary code with
| the elevated privileges of the program.  Exploitation requires an
| installed setuid or setgid binary whose DT_RPATH uses $ORIGIN
| followed by ".." traversal that normalizes into a trusted directory,
| and the ability to hard-link that binary and win the race by
| swapping a path component for a symbolic link. Major Linux-based OS
| distributions ship with fs.protected_hardlinks enabled by default
| and mitigate the vulnerability.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86805
https://www.cve.org/CVERecord?id=CVE-2026-86805
[1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore