CVE-2026-73585

Description

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.

Statement

Moderate: This flaw in sblim-cmpi-base provider registration scripts allows a local unprivileged attacker to overwrite root-owned files via a symlink attack in world-writable temporary directories. Exploitation requires specific conditions, including a privileged script execution and systems without sticky-directory symlink protections, which reduces its overall impact.

Mitigation

To mitigate this issue, ensure sticky-directory symlink protections are enabled on your system. This can be done immediately by running `sysctl -w fs.protected_symlinks=1`. To make this change persistent across reboots, create or modify a file in `/etc/sysctl.d/` (e.g., `/etc/sysctl.d/99-sysctl.conf`) with the content `fs.protected_symlinks=1` and then run `sysctl --system`. Additionally, avoid running the `sblim-cmpi-base` provider registration scripts from shared multi-user systems where untrusted users can create symlinks in `/tmp` or `/var/tmp`. If manual execution of the script is necessary, prefer using a private, root-owned temporary directory.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.3N/A6.3
Attack VectorLocalN/ALocal
Attack ComplexityHighN/AHigh
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

cve.org: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Understanding the Weakness (CWE)

Confidentiality,Integrity

Technical Impact: Read Files or Directories; Modify Files or Directories

Acknowledgements

This issue was discovered by Found by AISLE in partnership with Red Hat.

Frequently Asked Questions

Want to get errata notifications? Sign up here.