important · Linux privilege
A local Linux user can race gvfsd-admin into handing over a root-owned file and escalate to root.
Affects
GVfs, the GNOME virtual-filesystem service and its privileged admin backend on Linux desktops.
The race swaps a private socket pathname for a symlink before a privileged chown, allowing ownership of a security-sensitive root file to pass to the user.
Detail and 3 sources
CISA marks proof-of-concept exploitation, but we could not retrieve the upstream fix and do not know the corrected versions.