Description
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Published: 2026-09-10
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation to root via a TOCTOU race
Action: Apply Workaround
AI Analysis

Impact

The gvfsd-admin daemon modifies ownership of private D‑Bus sockets, but it does so by calling chown() on a pathname inside a user‑controlled directory. A local attacker can exploit a time‑of‑check to time‑of‑use race to replace the socket pathname with a symbolic link pointing to an arbitrary root‑owned file, such as /etc/pam.d/su. The daemon then follows the symlink and changes the file’s ownership to the attacker’s UID, allowing the attacker to modify critical system files and ultimately achieve full local privilege escalation to root.

Affected Systems

Red Hat Enterprise Linux 6 through 10 are affected. The vulnerability is present in the gvfs component of each of these distributions.

Risk and Exploitability

The CVSS score of 7 indicates high severity, and although the EPSS score is currently unavailable, the lack of listing in CISA’s KEV catalog does not negate the risk of exploitation. The required attacker model is a local user, and the vulnerability relies on a race condition that can be triggered by repeatedly creating socket paths. Successful exploitation would give the attacker UID 0 and full control over the affected system.

Generated by OpenCVE AI on September 10, 2026 at 15:52 UTC.

Remediation

Vendor Workaround

To mitigate this issue, adjust Polkit rules to require password authentication to start gvfsd-admin or remove execute permissions of the gvfsd-admin binary to prevent execution.


OpenCVE Recommended Actions

  • Adjust Polkit rules to require password authentication before a user can start gvfsd-admin
  • Remove execute permissions from the gvfsd-admin binary to prevent execution by unprivileged users
  • When an official vendor patch becomes available, apply it immediately

Generated by OpenCVE AI on September 10, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnome
Gnome gvfs
Vendors & Products Gnome
Gnome gvfs

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Gvfs: gvfs admin socket ownership race permits local root Gvfs: gvfs-admin socket ownership race permits local root

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Title Gvfs: gvfs admin socket ownership race permits local root
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-367
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Gnome Gvfs
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-30T17:07:44.836Z

Reserved: 2026-09-10T14:04:13.603Z

Link: CVE-2026-88924

cve-icon Vulnrichment

Updated: 2026-09-10T17:32:10.902Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T15:17:59.253

Modified: 2026-09-11T22:16:45.760

Link: CVE-2026-88924

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:00:00Z

Links: CVE-2026-88924 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:00:23Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition