CVE-2026-88924: Gnome Gvfs

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.

Affected products

  • Gnome Gvfs: from 1.48.1, before 1.62.0 (fixed in 1.62.0); from 1.48.1, before 1.60.3 (fixed in 1.60.3); from 1.48.1, before 1.58.5 (fixed in 1.58.5)
  • Red Hat Red Hat Enterprise Linux 10: before 0:1.54.4-4.el10_2.1 (fixed in 0:1.54.4-4.el10_2.1)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.48.1-8.el9_8.1 (fixed in 0:1.48.1-8.el9_8.1)

Published 2026-09-10. Last modified 2026-10-01.