PT-2026-51075 · Nuget · Corewcf.Unixdomainsocket

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-54778

CVSS v3.1

6.2

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Impact

Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.

Patches

Fixed in CoreWCF v1.8.1 and v1.9.1

Workarounds

Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54778
GHSA-Q6V9-43V5-JV9Q

Affected Products

Corewcf.Unixdomainsocket