Back

MEDIUM

Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling

Published Aug 13, 2026

Description

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

Affected products

Remediation

Vendor solution

To mitigate this issue, if instance migration is not required, run the `sfcbrepos` command with the `-i` option to disable the vulnerable migration path. For example: `sudo sfcbrepos -f -i`. Alternatively, avoid running `sfcbrepos` with elevated privileges on systems where untrusted local users can concurrently write to the `/tmp` directory. A service restart or reload may be required for changes to take effect if `sfcbrepos` is managed by a service.

Red Hat statement

This Moderate impact flaw in `sblim-sfcb` allows a local attacker to achieve privileged file corruption or denial of service through a time-of-check-to-time-of-use (TOCTOU) race condition. Exploitation requires a local low-privileged user to win a race during privileged `sfcbrepos` instance migration, which must be enabled and have specific repository content. The high attack complexity and specific preconditions limit its broader impact.

Red Hat mitigation

To mitigate this issue, if instance migration is not required, run the `sfcbrepos` command with the `-i` option to disable the vulnerable migration path. For example: `sudo sfcbrepos -f -i`. Alternatively, avoid running `sfcbrepos` with elevated privileges on systems where untrusted local users can concurrently write to the `/tmp` directory. A service restart or reload may be required for changes to take effect if `sfcbrepos` is managed by a service.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 13, 2026
Updated Aug 13, 2026
Reserved Aug 13, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Aug 25, 2026
Red Hat
Severity Moderate
Public date Aug 13, 2026