CVE-2026-12345
Description
A flaw was found in Python. A race condition during the cleanup of temporary directories allows a local attacker with write access to replace a directory with a symbolic link (a reference pointing to another location). This can lead to unauthorized deletion or alteration of files outside the temporary directory, performed with the privileges of the process executing the cleanup.
Statement
This vulnerability is rated as Moderate severity rather than Important because successful exploitation requires local system access, existing permissions to manipulate the target directory structure, and winning a narrow timing window during deletion. In Red Hat Enterprise Linux environments, standard temporary directory creation restricts access to the executing user, significantly limiting exposure to unprivileged local attackers. Applications running with elevated privileges that operate on shared or world-writable directories are at risk of unintended target file removal or permission tampering.
Mitigation
To mitigate this issue, ensure kernel symlink protection is enabled (active by default in RHEL) by verifying sysctl fs.protected_symlinks is set to 1. Additionally, restrict exposure on shared systems by setting the TMPDIR environment variable to a secure, user-private directory rather than a public shared path (e.g., export TMPDIR=/path/to/private_tmp).
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.3 | N/A | N/A |
| Attack Vector | Local | N/A | N/A |
| Attack Complexity | High | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | High | N/A | N/A |
| Availability Impact | High | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Understanding the Weakness (CWE)
Confidentiality,Integrity,Access Control
Technical Impact: Read Files or Directories; Modify Files or Directories; Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other
Technical Impact: Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.