THREAT OPS › Threat News › [NVD] CVE-2026-88924 (HIGH 7.0) — A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a T
[NVD] CVE-2026-88924 (HIGH 7.0) — A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a T
CVE-2026-88924 CVSS: 7.0 HIGH Published: 2026-09-10T15:17:59.253
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and e
Indicators of compromise
- CVE-2026-88924cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88924