Menu

#2776 sblim-cmpi-base: Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack (CVE-2026-73585)

Security
open
nobody
None
providers
5
4 days ago
4 days ago
No

Proposed fix attached.

Things worth mentioning, since they're behaviour changes rather than pure hardening:

  1. fix of the $TEMPDIR vs $_TEMPDIR typo (expansion to /delete-class.mof and fail for non-root) in pegasus_uninstall
  2. /var/tmp is no longer preferred over /tmp
  3. failure now returns 1 instead of continuing
1 Attachments

Discussion


Log in to post a comment.