Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
{
"cpe": "cpe:2.3:a:microsoft:windows_subsystem_for_linux:*:*:*:*:*:-:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.7.10"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"171973633138712228602800148505780346242",
"102458911898280980032178912928291844006",
"202975076359452292366516837974170055169",
"57818631525453842967122535841795536799",
"321359869844331781575573811342530666279"
]
},
"signature_version": "v1",
"source": "https://github.com/microsoft/wsl/commit/d35043c24e6d3d84b68dae1e862c20d67436f505",
"signature_type": "Line",
"target": {
"file": "src/windows/service/exe/LxssUserSession.cpp"
},
"id": "CVE-2026-57973-b7f16ca0",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"39732574636655132088782846837735297159",
"83066363709890614591310095556963098908",
"163989659712249552612366498029247588108"
]
},
"signature_version": "v1",
"source": "https://github.com/microsoft/wsl/commit/d35043c24e6d3d84b68dae1e862c20d67436f505",
"signature_type": "Line",
"target": {
"file": "test/windows/MountTests.cpp"
},
"id": "CVE-2026-57973-eb096631",
"deprecated": false
}
]
"2026-07-22T08:28:20Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57973.json"