Red Hat fixfiles script: race condition
Medium4.4CVE-2026-19079 · Published Aug 7, 2026 · updated Sep 1, 2026
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-367
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | Red Hat libvirt: user could define virtual networks to inject arbitrary | Low2.3 | No fix yet |
| Aug 7 | Red Hat dracut: command injection | High7.5 | No fix yet |
| Aug 7 | Red Hat p11-kit. A local attacker: integer overflow | Medium6.2 | No fix yet |
| Aug 6 | Red Hat udisks2: privilege escalation | High7.8 | Red Hat+1 more |
| Aug 6 | Red Hat GStreamer gst-plugins-good: denial of service | High7.5 | No fix yet |
| Aug 6 | Red Hat SAML broker: capture-replay | Medium6.4 | No fix yet |