Back

HIGH

Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target

Published Jul 15, 2026

Description

Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”).

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 15, 2026
Updated Jul 15, 2026
Reserved Jul 8, 2026
CISA Vulnrichment
Updated Jul 15, 2026
NVD
Status Awaiting Analysis
Modified Jul 15, 2026
Red Hat
Severity n/a
Public date n/a