PT-2026-51075 · Nuget · Corewcf.Unixdomainsocket
Publicado
2026-06-19
·
Atualizado
2026-06-19
·
CVE-2026-54778
CVSS v3.1
6.2
Média
| Vetor | AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
Impact
Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.
Patches
Fixed in CoreWCF v1.8.1 and v1.9.1
Workarounds
Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Corewcf.Unixdomainsocket