Race Condition in Snowflake Connector for .NET Affects Logging Configuration
CVE-2025-46326
What is CVE-2025-46326?
The Snowflake Connector for .NET is susceptible to a time-of-check to time-of-use (TOCTOU) race condition when using the Easy Logging feature on Linux and macOS. This issue arises as the Connector reads logging configuration from a user-specified file and checks if the configuration file can be written by its owner only. However, the verification process is flawed due to a TOCTOU vulnerability, potentially allowing a local attacker with write access to manipulate the configuration. Through this, the attacker can alter the logging level and output location, compromising the integrity of logging mechanisms. This vulnerability has been addressed in version 4.4.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
snowflake-connector-net >= 2.1.2, < 4.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
