Skip to finding
important · Linux privilege

A local Linux user can race gvfsd-admin into handing over a root-owned file and escalate to root.

Affects

GVfs, the GNOME virtual-filesystem service and its privileged admin backend on Linux desktops.

The race swaps a private socket pathname for a symlink before a privileged chown, allowing ownership of a security-sensitive root file to pass to the user.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026