What is CVE-2026-19079?
CVE-2026-19079 is a TOCTOU race condition vulnerability in the fixfiles script of policycoreutils. A local attacker can exploit the timing gap between the find and chcon commands used during relabeling operations on directories like /tmp to escalate privileges. Affected systems should be promptly patched.
Azərbaycanca: CVE-2026-19079, policycoreutils-in fixfiles skriptində aşkarlanmış TOCTOU (Time-of-Check Time-of-Use) yarış şərti zəifliyidir. /tmp kimi qovluqlarda etiketsiz faylları aşkarlayıb dəyişmək üçün istifadə olunan find və chcon əmrləri arasındakı zaman fərqindən istifadə edərək lokal hücumçu imtiyazları artıra bilər. Təsirə məruz qalan sistemlərdə dərhal yamaq tətbiq edilməlidir.
FAQ2
In which component was CVE-2026-19079 discovered?
CVE-2026-19079 was discovered in the fixfiles script of policycoreutils.
What can an attacker achieve by exploiting CVE-2026-19079?
A local attacker can escalate privileges by exploiting CVE-2026-19079.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.