CVE-2019-12779: Clusterlabs Libqb

High severity, CVSS 7.1. EPSS: 0.7% chance of exploitation in the next 30 days.

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

Affected products

Published 2019-06-07. Last modified 2026-06-17.