Impact
The gvfsd-admin daemon modifies ownership of private D‑Bus sockets, but it does so by calling chown() on a pathname inside a user‑controlled directory. A local attacker can exploit a time‑of‑check to time‑of‑use race to replace the socket pathname with a symbolic link pointing to an arbitrary root‑owned file, such as /etc/pam.d/su. The daemon then follows the symlink and changes the file’s ownership to the attacker’s UID, allowing the attacker to modify critical system files and ultimately achieve full local privilege escalation to root.
Affected Systems
Red Hat Enterprise Linux 6 through 10 are affected. The vulnerability is present in the gvfs component of each of these distributions.
Risk and Exploitability
The CVSS score of 7 indicates high severity, and although the EPSS score is currently unavailable, the lack of listing in CISA’s KEV catalog does not negate the risk of exploitation. The required attacker model is a local user, and the vulnerability relies on a race condition that can be triggered by repeatedly creating socket paths. Successful exploitation would give the attacker UID 0 and full control over the affected system.
OpenCVE Enrichment