PT-2026-51075 · Nuget · Corewcf.Unixdomainsocket

Publicado

2026-06-19

·

Atualizado

2026-06-19

·

CVE-2026-54778

CVSS v3.1

6.2

Média

VetorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Impact

Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.

Patches

Fixed in CoreWCF v1.8.1 and v1.9.1

Workarounds

Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-54778
GHSA-Q6V9-43V5-JV9Q

Produtos afetados

Corewcf.Unixdomainsocket