Back

MEDIUM

systemd: systemd-tmpfiles symlink-redirected arbitrary file overwrite via a CHASE_SAFE root-to-unprivileged ownership transition bypass

Published Jul 22, 2026

Description

Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.

Affected products

Remediation

Red Hat statement

This CVE has been marked as rejected by the assigning CNA.

Red Hat mitigation

Restrict or audit any custom tmpfiles.d configuration entries (e.g. authored via configuration-management tooling) that use the 'w' item type against paths under /run/user/*, per-user home directories, or other locations where an unprivileged user can influence path resolution, until an upstream fix is available.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner EUVD
Published Jul 22, 2026
Updated n/a
Reserved n/a
NVD
Status Rejected
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date Jul 22, 2026
ENISA EUVD
Assigner redhat
Published Jul 22, 2026
Updated Jul 23, 2026
Exploited since n/a
EUVD-2026-47736