Skip to main content
Vulnerability Database/CVE-2026-86805

CVE-2026-86805: GNU C Library Privilege Escalation Vulnerability

CVE-2026-86805 is a TOCTOU race condition in GNU C Library dynamic loader affecting versions 2.14 through 2.44, allowing local privilege escalation. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-86805 Overview

CVE-2026-86805 is a time-of-check to time-of-use (TOCTOU) race condition [CWE-367] in the dynamic loader (ld.so) of the GNU C Library (glibc), affecting versions 2.14 through 2.44. The flaw exists in how the loader expands $ORIGIN inside DT_RPATH for setuid and setgid programs running under AT_SECURE. A local attacker who can hard-link a vulnerable program and win a race by replacing a path component with a symbolic link can load an attacker-controlled shared object. Successful exploitation grants code execution with the elevated privileges of the target binary.

Critical Impact

Local privilege escalation to the effective UID or GID of any qualifying setuid/setgid binary on systems where fs.protected_hardlinks is disabled.

Affected Products

  • GNU C Library (glibc) versions 2.14 through 2.44
  • Linux systems with fs.protected_hardlinks sysctl disabled
  • Systems shipping setuid/setgid binaries whose DT_RPATH uses $ORIGIN with .. traversal

Discovery Timeline

  • 2026-09-22 - CVE-2026-86805 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-86805

Vulnerability Analysis

The glibc dynamic loader supports the $ORIGIN token inside DT_RPATH entries to allow binaries to locate sibling libraries relative to their own path. For setuid or setgid programs marked AT_SECURE, the loader must confirm that any expanded path resolves inside a trusted directory before loading libraries from it. The vulnerability arises because the loader validates a lexically normalized version of the path but then opens the raw, un-normalized path. This split between the checked value and the used value creates the classic TOCTOU condition that CWE-367 describes.

An attacker who hard-links the setuid binary into a directory they control gains authority over the resolution of $ORIGIN. By racing to swap an intermediate directory component with a symbolic link, the attacker redirects the actual open() call outside the trusted directory. The loader then maps an attacker-supplied shared object into the privileged process.

Root Cause

The root cause is inconsistent path handling inside ld.so when processing DT_RPATH under AT_SECURE. The trusted-directory check operates on the normalized string, while the subsequent library load operates on the raw string containing .. traversal. A concurrent filesystem mutation between check and use invalidates the security guarantee the check was meant to enforce.

Attack Vector

Exploitation requires local access and several preconditions. The target system must have fs.protected_hardlinks disabled, which is not the default on major Linux distributions. A setuid or setgid binary must exist whose DT_RPATH contains $ORIGIN followed by .. sequences that normalize into a trusted directory such as /lib or /usr/lib. The attacker hard-links the binary into a writable directory, prepares a malicious shared object matching the library name the loader will request, and repeatedly executes the binary while swapping a path component for a symlink to win the race. The attack complexity is high because it depends on race timing and specific binary metadata, and the exploit requires the launched program to reach the vulnerable load path.

No verified public exploit code is available. See the Sourceware GLIBC Security Advisory and Sourceware Bug Report #34360 for technical details.

Detection Methods for CVE-2026-86805

Indicators of Compromise

  • Hard links to setuid or setgid binaries located in user-writable directories such as /tmp, /var/tmp, or home directories
  • Unexpected shared object files placed in directories adjacent to hard-linked setuid binaries
  • Repeated executions of a setuid binary from a non-standard path within a short window, consistent with race-condition brute forcing
  • execve events where the resolved library path deviates from expected system library directories

Detection Strategies

  • Audit the filesystem for setuid and setgid binaries whose DT_RPATH contains $ORIGIN with .. traversal using readelf -d or objdump -x
  • Query the current state of fs.protected_hardlinks on every Linux host and flag any host where the value is 0
  • Monitor openat and open syscalls issued by ld.so for setuid processes that resolve outside standard trusted directories

Monitoring Recommendations

  • Enable Linux Auditd rules for execve on setuid binaries and for link/linkat operations that target setuid executables
  • Alert on symlink creation events inside directories that also contain hard links to system binaries
  • Track sysctl configuration drift and alert when fs.protected_hardlinks transitions from 1 to 0

How to Mitigate CVE-2026-86805

Immediate Actions Required

  • Confirm fs.protected_hardlinks=1 is set and persistent across reboots on all Linux hosts
  • Inventory setuid and setgid binaries whose DT_RPATH uses $ORIGIN with .. traversal and remove the setuid bit where not required
  • Apply glibc updates from your distribution as soon as fixed packages become available
  • Restrict local shell access on multi-user systems until patches are deployed

Patch Information

Fixes are tracked upstream through Sourceware Bug Report #34360 and the Sourceware GLIBC Security Advisory. Apply distribution-supplied glibc packages once they include the corrected $ORIGIN handling in ld.so. Major Linux distributions already mitigate the issue by shipping with fs.protected_hardlinks enabled by default.

Workarounds

  • Ensure fs.protected_hardlinks=1 by adding it to /etc/sysctl.d/ and applying with sysctl --system
  • Remove the setuid or setgid bit from binaries that rely on $ORIGIN-based DT_RPATH when they are not required for normal operation
  • Rebuild affected binaries without $ORIGIN traversal in DT_RPATH, using absolute trusted paths instead
bash
# Enforce hard-link protection to mitigate CVE-2026-86805
echo 'fs.protected_hardlinks = 1' | sudo tee /etc/sysctl.d/99-cve-2026-86805.conf
sudo sysctl --system
sysctl fs.protected_hardlinks

# Identify setuid/setgid binaries using $ORIGIN in DT_RPATH
find / -xdev \( -perm -4000 -o -perm -2000 \) -type f 2>/dev/null \
  | while read -r bin; do
      readelf -d "$bin" 2>/dev/null \
        | grep -E 'RPATH|RUNPATH' \
        | grep -q '\$ORIGIN.*\.\.' && echo "CHECK: $bin"
    done

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.