<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:44:35.690445+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-22701</id>
    <title>BREW-aider-CVE-2026-22701 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
    <updated>2026-10-04T01:44:36.575540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>## Vulnerability Summary</p>
<p>**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</p>
<p>**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59</p>
<p>---</p>
<p>## Description</p>
<p>A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.</p>
<p>The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.</p>
<p>### Attack Scenario</p>
<p>```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```</p>
<p>---</p>
<p>## Impact</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.</p>
<p>**Affected Users:**
- Applications using `filelock.SoftFil…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-22701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</id>
    <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T01:44:36.575632+00:00</updated>
    <content>certfr-2026-avi-0224</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bi98027</id>
    <title>CLEANSTART-2026-BI98027 — Security fix for CVE-2026-22701 applied in: kserve-storage-controller 0.19.0-r0</title>
    <updated>2026-10-04T01:44:36.575653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: kserve-storage-controller</p>
<p>Security vulnerability affects the kserve-storage-controller package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bi98027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265407</id>
    <title>EUVD-2026-265407</title>
    <updated>2026-10-04T01:44:36.575674+00:00</updated>
    <content>EUVD-2026-265407</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22701</id>
    <title>fkie_cve-2026-22701</title>
    <updated>2026-10-04T01:44:36.575686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qmgc-5h2g-mvrw</id>
    <title>GHSA-qmgc-5h2g-mvrw — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
    <updated>2026-10-04T01:44:36.575709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: filelock</p>
<p>## Vulnerability Summary</p>
<p>**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</p>
<p>**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59</p>
<p>---</p>
<p>## Description</p>
<p>A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.</p>
<p>The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.</p>
<p>### Attack Scenario</p>
<p>```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```</p>
<p>---</p>
<p>## Impact</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.</p>
<p>**Affected Users:**
- Applications using `filelock.SoftFil…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qmgc-5h2g-mvrw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-22701</id>
    <title>msrc_CVE-2026-22701 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
    <updated>2026-10-04T01:44:36.575758+00:00</updated>
    <content>msrc_CVE-2026-22701</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-22701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1237</id>
    <title>OESA-2026-1237 — python-filelock security update</title>
    <updated>2026-10-04T01:44:36.575774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: python-filelock</p>
<p>This package contains a single module, which implements a platform independent file locking mechanism for Python.

Security Fix(es):</p>
<p>filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.(CVE-2026-22701)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10043-1</id>
    <title>openSUSE-SU-2026:10043-1 — python311-filelock-3.20.3-1.1 on GA media</title>
    <updated>2026-10-04T01:44:36.575799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-filelock-3.20.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10043-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1374</id>
    <title>PYSEC-2026-1374 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
    <updated>2026-10-04T01:44:36.575814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: filelock</p>
<p>## Vulnerability Summary</p>
<p>**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</p>
<p>**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59</p>
<p>---</p>
<p>## Description</p>
<p>A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.</p>
<p>The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.</p>
<p>### Attack Scenario</p>
<p>```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```</p>
<p>---</p>
<p>## Impact</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.</p>
<p>**Affected Users:**
- Applications using `filelock.SoftFil…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20216-1</id>
    <title>SUSE-SU-2026:20216-1 — Security update for python-filelock</title>
    <updated>2026-10-04T01:44:36.575860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-filelock</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20216-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22701</id>
    <title>UBUNTU-CVE-2026-22701</title>
    <updated>2026-10-04T01:44:36.575875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: python-filelock, Ubuntu:Pro:22.04:LTS: python-filelock, Ubuntu:Pro:24.04:LTS: python-filelock, Ubuntu:25.10: python-filelock, Ubuntu:26.04:LTS: python-filelock</p>
<p>filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22701"/>
  </entry>
</feed>
