TOCTOU Race Condition Vulnerability in Policycoreutils by SELinux
CVE-2026-59676

5.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-59676?

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability has been identified in the 'seunshare' feature of the policycoreutils package in SELinux. This vulnerability allows an unauthorized user executing 'seunshare' within the unconfined SELinux domain to manipulate the access control, thereby enabling them to delete arbitrary root-owned files. This raises significant security concerns, as it can lead to unauthorized data access and potential system compromises.

Affected Version(s)

selinux 0 <= 3.10

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.