SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
{
"cna_assigner": "sba-research",
"cwe_ids": [
"CWE-367"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41259.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-41259.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "89529434304315812385780302496230342401",
"length": 634
},
"id": "CVE-2025-41259-39501b54",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d",
"target": {
"file": "core/util.c",
"function": "swupdate_remove_directory"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"244392430412439603036487102069731633187",
"173388438307855236941269846073740091773",
"12652183546458038736969437918408029488",
"275813714068425932503340476201464589050",
"301037403177265941945846514348303833616",
"114917503296895387442606474211509284792",
"120594897682487706085760629067832957018",
"88348980539232767229855587301500979699",
"138257688947722297478605601658938613096"
],
"threshold": 0.9
},
"id": "CVE-2025-41259-ed94379b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d",
"target": {
"file": "core/util.c"
}
}
]
"2026-08-12T11:28:52Z"