Symbolic Link Vulnerability in systemd-tmpfiles Affects Users
CVE-2026-16552

6.3MEDIUM

What is CVE-2026-16552?

A security flaw exists in systemd-tmpfiles that allows unprivileged local users to exploit symbolic links in tmpfiles.d configuration entries. When processing these entries, the systemd-tmpfiles utility may follow a symbolic link created by a non-privileged user, which can lead to unauthorized file redirection. This flaw circumvents an existing safety check that assumes transitions away from the root user as safe, potentially compromising the integrity of the system. Even though the content written by tmpfiles.d is determined by existing configurations, the ability to redirect writes to arbitrary files poses a significant risk.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank İbrahim Sağlam (Eresus Security) for reporting this issue.
.