Local File Overwrite Vulnerability in Linenoise from Antirez
CVE-2025-9810

6.8MEDIUM

Key Information:

Vendor

Antirez

Status
Vendor
CVE Published:
1 September 2025

What is CVE-2025-9810?

A local file overwrite vulnerability exists in Linenoise due to a Time of Check to Time of Use (TOCTOU) race condition. This flaw allows local attackers to exploit symlink manipulation by performing a race between file creation (fopen with write access) and permission changes (chmod) on the same file path. Successfully exploiting this vulnerability can lead to unauthorized file modifications and permission escalation, making it crucial for users to implement security best practices and monitor for suspicious activities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

linenoise 0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@disconnect3d
Simcha Kosman
.