Red Hat cockpit-files. This vulnerability: race condition
Medium6.0CVE-2026-91203 · Published Sep 18, 2026 · updated Sep 22, 2026
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-363
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | Red Hat OpenShift Container Platform 4: server-side request forgery | Critical9.3 | No fix yet |
| Sep 18 | Red Hat Netty: request smuggling | Medium6.5 | No fix yet |
| Sep 18 | Red Hat Netty: request smuggling | Medium6.5 | No fix yet |
| Sep 18 | A flaw was found in cockpit-files | Medium6.1 | No fix yet |
| Sep 18 | Red Hat cockpit-files: race condition | Medium6.0 | No fix yet |
| Sep 18 | Red Hat libsmpp34: memory corruption | High7.5 | 1.14.5 |