CVE-2026-88924

NameCVE-2026-88924
DescriptionA flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147399

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gvfs (PTS)bookworm1.50.3-1+deb12u1vulnerable
trixie1.57.2-2+deb13u1vulnerable
forky, sid1.62.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gvfssource(unstable)1.62.0-11147399

Notes

[trixie] - gvfs <no-dsa> (Minor issue)
https://gitlab.gnome.org/GNOME/gvfs/-/issues/875
https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/352
Introduced with: https://gitlab.gnome.org/GNOME/gvfs/-/commit/5f9cffd11dc69a9422726a059c7c31bae4b46338 (1.48.1)
Fixed by: https://gitlab.gnome.org/GNOME/gvfs/-/commit/371909dd201eb66c5c4d18d9e88fdae4a070b76a (1.62.0)

Search for package or bug name: Reporting problems