On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:10217 https://access.redhat.com/errata/RHSA-2026:10217
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:10219 https://access.redhat.com/errata/RHSA-2026:10219
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:10704 https://access.redhat.com/errata/RHSA-2026:10704
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11507 https://access.redhat.com/errata/RHSA-2026:11507
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11514 https://access.redhat.com/errata/RHSA-2026:11514
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11704 https://access.redhat.com/errata/RHSA-2026:11704
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11712 https://access.redhat.com/errata/RHSA-2026:11712
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11711 https://access.redhat.com/errata/RHSA-2026:11711
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11863 https://access.redhat.com/errata/RHSA-2026:11863
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:14200 https://access.redhat.com/errata/RHSA-2026:14200
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:14391 https://access.redhat.com/errata/RHSA-2026:14391