Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96612.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96612
Upstream
  • CVE-2026-73584
Published
2026-08-13T13:19:18Z
Modified
2026-09-20T05:32:18Z
Summary
CVE-2026-73584 affecting package sblim-sfcb 1.4.9-20
Details

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the /tmp directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.

References

Affected packages

Azure Linux:3 / sblim-sfcb

Package

Name
sblim-sfcb
Purl
pkg:rpm/azure-linux/sblim-sfcb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.4.9-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96612.json"