Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling
Published Aug 13, 2026
6.3
MEDIUMCVSS 3.1
EPSS 0.13%
Description
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
sblim-sfcb
Fix deferred
Red Hat Enterprise Linux 6
sblim-sfcb
Out of support scope
Red Hat Enterprise Linux 7
sblim-sfcb
Fix deferred
Red Hat Enterprise Linux 8
sblim-sfcb
Fix deferred
Red Hat Enterprise Linux 9
sblim-sfcb
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | sblim-sfcb | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | sblim-sfcb | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | sblim-sfcb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | sblim-sfcb | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | sblim-sfcb | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, if instance migration is not required, run the `sfcbrepos` command with the `-i` option to disable the vulnerable migration path. For example: `sudo sfcbrepos -f -i`. Alternatively, avoid running `sfcbrepos` with elevated privileges on systems where untrusted local users can concurrently write to the `/tmp` directory. A service restart or reload may be required for changes to take effect if `sfcbrepos` is managed by a service.
Red Hat statement
This Moderate impact flaw in `sblim-sfcb` allows a local attacker to achieve privileged file corruption or denial of service through a time-of-check-to-time-of-use (TOCTOU) race condition. Exploitation requires a local low-privileged user to win a race during privileged `sfcbrepos` instance migration, which must be enabled and have specific repository content. The high attack complexity and specific preconditions limit its broader impact.
Red Hat mitigation
To mitigate this issue, if instance migration is not required, run the `sfcbrepos` command with the `-i` option to disable the vulnerable migration path. For example: `sudo sfcbrepos -f -i`. Alternatively, avoid running `sfcbrepos` with elevated privileges on systems where untrusted local users can concurrently write to the `/tmp` directory. A service restart or reload may be required for changes to take effect if `sfcbrepos` is managed by a service.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.13% (0.00126) | 1.98th | v5 (v2026.06.15) |
| Aug 14, 2026 | 0.09% (0.00091) | 0.57th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-73584 vdb-entryx_refsource_REDHATVendor AdvisoryMitigation
- https://bugzilla.redhat.com/show_bug.cgi?id=2462721 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73584
- https://www.cve.org/CVERecord?id=CVE-2026-73584
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-73584 | vdb-entryx_refsource_REDHATVendor AdvisoryMitigation | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2462721 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73584 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73584 |
Change history (0)
No recorded changes yet.