Race Condition Vulnerability in Policycoreutils by Red Hat
CVE-2026-19079
4.4MEDIUM
What is CVE-2026-19079?
A race condition vulnerability exists in the fixfiles script of Policycoreutils, allowing a local attacker to exploit the gap between file discovery and label changes. By using symlinks to swap directory components, the attacker can manipulate SELinux labels on critical system files, such as /etc/shadow. This risk potentially compromises SELinux's mandatory access control measures, which are crucial for maintaining system security. Proper application of security practices is essential to mitigate this vulnerability.
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Stephen Smalley as the original reporter.