CVE-2026-57973

Source
https://cve.org/CVERecord?id=CVE-2026-57973
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57973.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-57973
Published
2026-07-14T18:18:35.460Z
Modified
2026-07-22T08:28:20.028195Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

References

Affected packages

Git / github.com/microsoft/wsl

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/wsl
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:microsoft:windows_subsystem_for_linux:*:*:*:*:*:-:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.7.10"
        }
    ]
}

Affected versions

0.*
0.47.1
0.48.2
0.50.2
0.51.0
0.51.2
0.51.3
0.56.1
0.56.2
0.58.0
0.58.1
0.58.3
0.60.0
0.61.4
0.61.5
0.61.8
0.64.0
0.65.1
0.65.2
0.65.3
0.66.2
0.67.6
0.68.2
0.68.4
0.70.0
0.70.4
0.70.5
0.70.8
1.*
1.0.0
1.0.1
1.0.3
1.1.0
1.1.2
1.1.3
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.3.10
1.3.11
1.3.14
1.3.15
1.3.17
2.*
2.0.0
2.0.1
2.0.11
2.0.12
2.0.14
2.0.15
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.3
2.1.4
2.1.5
2.2.1
2.2.2
2.2.3
2.2.4
2.3.11
2.3.12
2.3.13
2.3.14
2.3.17
2.3.21
2.3.22
2.3.24
2.3.25
2.3.26
2.4.10
2.4.11
2.4.12
2.4.13
2.4.4
2.4.5
2.4.8
2.4.9
2.5.1
2.5.10
2.5.4
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "171973633138712228602800148505780346242",
                "102458911898280980032178912928291844006",
                "202975076359452292366516837974170055169",
                "57818631525453842967122535841795536799",
                "321359869844331781575573811342530666279"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/microsoft/wsl/commit/d35043c24e6d3d84b68dae1e862c20d67436f505",
        "signature_type": "Line",
        "target": {
            "file": "src/windows/service/exe/LxssUserSession.cpp"
        },
        "id": "CVE-2026-57973-b7f16ca0",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "39732574636655132088782846837735297159",
                "83066363709890614591310095556963098908",
                "163989659712249552612366498029247588108"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/microsoft/wsl/commit/d35043c24e6d3d84b68dae1e862c20d67436f505",
        "signature_type": "Line",
        "target": {
            "file": "test/windows/MountTests.cpp"
        },
        "id": "CVE-2026-57973-eb096631",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T08:28:20Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57973.json"