[COMMITTED] Publish CVE-2026-86805 advisory

Carlos O'Donell carlos@redhat.com
Tue Sep 22 15:48:18 GMT 2026


Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>
Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
---
 advisories/GLIBC-SA-2026-0022 | 28 ++++++++++++++++++++++++++++
 1 file changed, 28 insertions(+)
 create mode 100644 advisories/GLIBC-SA-2026-0022

diff --git a/advisories/GLIBC-SA-2026-0022 b/advisories/GLIBC-SA-2026-0022
new file mode 100644
index 0000000000..fde0afac6a
--- /dev/null
+++ b/advisories/GLIBC-SA-2026-0022
@@ -0,0 +1,28 @@
+AT_SECURE programs may load attacker-controlled code via $ORIGIN
+
+A time-of-check to time-of-use (TOCTOU) race condition in the dynamic
+loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44
+allows a local attacker to escalate privileges. When expanding $ORIGIN
+in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the
+lexically normalized search path against the trusted directories but
+then opens the raw, un-normalized path. On systems where the Linux
+fs.protected_hardlinks sysctl is disabled, a local attacker who
+hard-links such a program into an attacker-controlled directory and wins
+a race to replace an intermediate path component with a symbolic link
+can direct the loader outside the trusted directory, causing it to load
+an attacker-controlled shared object and execute arbitrary code with the
+elevated privileges of the program.
+
+Exploitation requires an installed setuid or setgid binary whose DT_RPATH
+uses $ORIGIN followed by ".." traversal that normalizes into a trusted
+directory, and the ability to hard-link that binary and win the race by
+swapping a path component for a symbolic link. Major Linux-based OS
+distributions ship with fs.protected_hardlinks enabled by default and
+mitigate the vulnerability.
+
+CVE-Id: CVE-2026-86805 
+Public-Date: 2026-07-06
+Vulnerable-Commit: 47c3cd7a74e8c089d60d603afce6d9cf661178d6 (2.13-113)
+Fix-Commit: ed0c137b97eb940b4b64981e84ed806d3276edd9 (2.45) 
+Reported-by: Jann Horn <jannh@google.com>
+CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - 7.0
-- 
2.55.0



More information about the Libc-alpha mailing list