Bug 2456336 (CVE-2026-32282)
| Summary: | CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aazores, abarbaro, abrianik, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aruklets, asatyam, ataylor, bbrownin, bdettelb, bniver, bparees, chfoley, ckandaga, cmah, crizzo, csutherl, dakwon, dbruscin, dhanak, diagrawa, dkeler, dmayorov, doconnor, drosa, dschmidt, dsimansk, dsoumis, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, ehugonne, erezende, ewittman, fdeutsch, flucifre, ggainey, ggrzybek, gmeno, gparvin, groman, hasun, ibolton, janstey, jbalunas, jbritton, jburrell, jcantril, jchui, jclere, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jraez, jschluet, juwatts, jwon, kingland, kshier, ktsao, kvanderr, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, lphiri, manissin, mbenjamin, mbocek, mburns, mgarciac, mhackett, mhess, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pcreech, peholase, pgaikwad, pjindal, plodge, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmaucher, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, szappis, tasato, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vle, vvoronko, vwilson, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before acting, the `chmod` operation will be performed on the file the symbolic link points to. This issue can bypass directory restrictions and lead to unauthorized permission changes on the filesystem.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2456942 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-08 02:01:35 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:10217 https://access.redhat.com/errata/RHSA-2026:10217 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:10219 https://access.redhat.com/errata/RHSA-2026:10219 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:10704 https://access.redhat.com/errata/RHSA-2026:10704 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11507 https://access.redhat.com/errata/RHSA-2026:11507 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11514 https://access.redhat.com/errata/RHSA-2026:11514 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11704 https://access.redhat.com/errata/RHSA-2026:11704 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11712 https://access.redhat.com/errata/RHSA-2026:11712 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11711 https://access.redhat.com/errata/RHSA-2026:11711 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11863 https://access.redhat.com/errata/RHSA-2026:11863 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:14200 https://access.redhat.com/errata/RHSA-2026:14200 This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:14391 https://access.redhat.com/errata/RHSA-2026:14391 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:15980 https://access.redhat.com/errata/RHSA-2026:15980 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:16024 https://access.redhat.com/errata/RHSA-2026:16024 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:16021 https://access.redhat.com/errata/RHSA-2026:16021 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:16875 https://access.redhat.com/errata/RHSA-2026:16875 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:17075 https://access.redhat.com/errata/RHSA-2026:17075 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:17084 https://access.redhat.com/errata/RHSA-2026:17084 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:18027 https://access.redhat.com/errata/RHSA-2026:18027 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:18032 https://access.redhat.com/errata/RHSA-2026:18032 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19132 https://access.redhat.com/errata/RHSA-2026:19132 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19133 https://access.redhat.com/errata/RHSA-2026:19133 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19134 https://access.redhat.com/errata/RHSA-2026:19134 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19136 https://access.redhat.com/errata/RHSA-2026:19136 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19135 https://access.redhat.com/errata/RHSA-2026:19135 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19144 https://access.redhat.com/errata/RHSA-2026:19144 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19156 https://access.redhat.com/errata/RHSA-2026:19156 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19350 https://access.redhat.com/errata/RHSA-2026:19350 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19351 https://access.redhat.com/errata/RHSA-2026:19351 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19352 https://access.redhat.com/errata/RHSA-2026:19352 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19353 https://access.redhat.com/errata/RHSA-2026:19353 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19369 https://access.redhat.com/errata/RHSA-2026:19369 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19550 https://access.redhat.com/errata/RHSA-2026:19550 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19714 https://access.redhat.com/errata/RHSA-2026:19714 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19715 https://access.redhat.com/errata/RHSA-2026:19715 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19719 https://access.redhat.com/errata/RHSA-2026:19719 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:19721 https://access.redhat.com/errata/RHSA-2026:19721 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:19720 https://access.redhat.com/errata/RHSA-2026:19720 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:19722 https://access.redhat.com/errata/RHSA-2026:19722 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19750 https://access.redhat.com/errata/RHSA-2026:19750 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:19839 https://access.redhat.com/errata/RHSA-2026:19839 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:20556 https://access.redhat.com/errata/RHSA-2026:20556 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22141 https://access.redhat.com/errata/RHSA-2026:22141 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22450 https://access.redhat.com/errata/RHSA-2026:22450 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:22709 https://access.redhat.com/errata/RHSA-2026:22709 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:22714 https://access.redhat.com/errata/RHSA-2026:22714 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22937 https://access.redhat.com/errata/RHSA-2026:22937 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:23228 https://access.redhat.com/errata/RHSA-2026:23228 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:24337 https://access.redhat.com/errata/RHSA-2026:24337 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:24716 https://access.redhat.com/errata/RHSA-2026:24716 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:24762 https://access.redhat.com/errata/RHSA-2026:24762 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2026:24761 https://access.redhat.com/errata/RHSA-2026:24761 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:25999 https://access.redhat.com/errata/RHSA-2026:25999 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:27076 https://access.redhat.com/errata/RHSA-2026:27076 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:27732 https://access.redhat.com/errata/RHSA-2026:27732 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:28038 https://access.redhat.com/errata/RHSA-2026:28038 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2026:28046 https://access.redhat.com/errata/RHSA-2026:28046 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2026:28047 https://access.redhat.com/errata/RHSA-2026:28047 This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:28385 https://access.redhat.com/errata/RHSA-2026:28385 This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:34366 https://access.redhat.com/errata/RHSA-2026:34366 This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:34368 https://access.redhat.com/errata/RHSA-2026:34368 This issue has been addressed in the following products: RHEM 1.0 for RHEL 9 Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796 This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:39810 https://access.redhat.com/errata/RHSA-2026:39810 Added rhem-1.1/flightctl affect and tracker. This stream was missing affects for this CVE since it went GA after the triage, but it's still vulnerable. This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019 |