Bug 2543492 (CVE-2026-12345)
| Summary: | CVE-2026-12345 python: python: Arbitrary file deletion via race condition during temporary directory cleanup | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bbrownin, cahl, dfreiber, dkeler, drow, dschmidt, gbenhaim, ikhan, jburrell, jlanda, kshier, ljawale, msilmser, niyer, rbobbitt, rhel-process-autobot, simaishi, stcannon, suppawar, thason, twaugh, vkumar, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Python. A race condition during the cleanup of temporary directories allows a local attacker with write access to replace a directory with a symbolic link (a reference pointing to another location). This can lead to unauthorized deletion or alteration of files outside the temporary directory, performed with the privileges of the process executing the cleanup.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2547342, 2547343, 2547344, 2547345, 2547346, 2547347, 2547348, 2547349, 2547350, 2547351, 2547352, 2547353 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-29 18:37:57 UTC
|