| Name | CVE-2026-59676 |
| Description | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| policycoreutils (PTS) | bullseye | 3.1-3 | fixed |
| bookworm | 3.4-1 | fixed |
| trixie | 3.8.1-2 | fixed |
| forky, sid | 3.11-1 | fixed |
| selinux-python (PTS) | bullseye | 3.1-1 | fixed |
| bookworm | 3.4-1 | fixed |
| trixie | 3.8.1-2 | fixed |
| forky | 3.10-1 | fixed |
| sid | 3.11-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[bookworm] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
[bullseye] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building
policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a
separate upstream package.
https://security.opensuse.org/2026/07/15/selinux-seunshare.html