Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99993.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99993
Upstream
  • CVE-2026-86469
Published
2026-09-07T16:17:30Z
Modified
2026-09-14T05:26:59Z
Summary
CVE-2026-86469 affecting package glib 2.78.6-11
Details

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

References

Affected packages

Azure Linux:3 / glib

Package

Name
glib
Purl
pkg:rpm/azure-linux/glib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.78.6-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99993.json"