THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-88924 (HIGH 7.0) — A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a T

[NVD] CVE-2026-88924 (HIGH 7.0) — A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a T

mednvdPublished 2026-09-10

CVE-2026-88924 CVSS: 7.0 HIGH Published: 2026-09-10T15:17:59.253

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and e

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88924