Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
7.0
CVE-2026-88924EXPLOITEDPATCHED
red hat · red hat enterprise linux

Gvfs: gvfs-admin socket ownership race permits local root

Description

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.

Affected Products

VendorProductVersions
red hatred hat enterprise linux1.48.1, 1.48.1, 1.48.1

References

  • https://access.redhat.com/security/cve/CVE-2026-88924(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2531456(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/gvfs/-/issues/875

Related News (2 articles)

Tier D
Help Net Security3d ago
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-88924 | Red Hat Enterprise Linux up to 10 gvfsd-admin chown toctou
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.0 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
*
CWECWE-367
PublishedSep 10, 2026
Last enriched17d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score35
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-96280EXP
Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
Trending: 45
MEDIUMCVE-2026-96281EXP
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
Trending: 41
LOWCVE-2026-96284EXP
Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following
Trending: 40
NONECVE-2026-97185EXP
Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
Trending: 36
CRITICALCVE-2026-96276EXP
Flatpak: flatpak: arbitrary write in host context via flatpak build-init
Trending: 33

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 10, 2026
Discovered by ZDM
Sep 10, 2026
Actively Exploited
Sep 11, 2026
Exploit Available
Sep 11, 2026
Patch Available
Sep 11, 2026