CVE-2026-1386
Description
A flaw was found in the Firecracker jailer component. A local user with write access to pre-created jailer directories could exploit a symbolic link (symlink) following issue. This vulnerability allows the attacker to overwrite arbitrary host files during the jailer's startup initialization process, provided the jailer is executed with root privileges. This could lead to unauthorized modification of system files.
Statement
This vulnerability is rated Moderate for Red Hat. A local host user with write access to pre-created jailer directories can exploit a symbolic link following issue in the Firecracker jailer component. This allows for arbitrary host file overwrite via a symlink attack during jailer startup, provided the jailer is executed with root privileges.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Confidentiality,Integrity
Technical Impact: Read Files or Directories; Modify Files or Directories
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.