CVE-2026-86469

NameCVE-2026-86469
DescriptionA flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147411

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glib2.0 (PTS)bookworm2.74.6-2+deb12u9vulnerable
bookworm (security)2.74.6-2+deb12u2vulnerable
trixie2.84.4-3~deb13u5vulnerable
forky, sid2.90.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glib2.0source(unstable)(unfixed)1147411

Notes

[trixie] - glib2.0 <no-dsa> (Minor issue)
[bookworm] - glib2.0 <postponed> (Minor issue, require working in attacker-controlled directory)
https://bugzilla.redhat.com/show_bug.cgi?id=2473839
https://gitlab.gnome.org/GNOME/glib/-/work_items/4044

Search for package or bug name: Reporting problems