Race Condition Vulnerability in Policycoreutils by Red Hat
CVE-2026-19079

4.4MEDIUM

What is CVE-2026-19079?

A race condition vulnerability exists in the fixfiles script of Policycoreutils, allowing a local attacker to exploit the gap between file discovery and label changes. By using symlinks to swap directory components, the attacker can manipulate SELinux labels on critical system files, such as /etc/shadow. This risk potentially compromises SELinux's mandatory access control measures, which are crucial for maintaining system security. Proper application of security practices is essential to mitigate this vulnerability.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Stephen Smalley as the original reporter.
.