Skip to content
Red HatCVE-2026-73585

A flaw was found in sblim-cmpi-base

Medium6.3CVE-2026-73585 · Published Aug 13, 2026 · updated Aug 25, 2026

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-377

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform 2: incomplete cleanup
Medium4.2Aug 13
A flaw was found in the clusterclaims-controller component of Multicluster...
High7.1Aug 13
Red Hat sblim-sfcb: unsafe deserialization
Medium6.6Aug 13
Red Hat sblim-sfcb. A local: race condition
Medium6.3Aug 13
Red Hat open-iscsi. An integer underflow vulnerability: integer overflow
Medium6.5Aug 13
Red Hat: mass assignment
High8.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.