CVE-2026-73585

Discovered by AISLEPUBLISHEDCWE-377

Description

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.

CVSS Base Scores

CVSS v3.1(Primary)
6.3

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 10——
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat Enterprise Linux 9——

Credits

  • This issue was discovered by Found by AISLE in partnership with Red Hat.

References