🔐 CVE Alert

CVE-2026-59676

UNKNOWN 0.0

Local File Deletion Attack Vector in rm_rf() in seunshare

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

CWE CWE-367
Vendor selinuxproject
Product selinux
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for selinuxproject selinux

Be the first to know when new unknown vulnerabilities affecting selinuxproject selinux are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

SELinuxProject / selinux
0 ≤ 3.10

References

NVD ↗ CVE.org ↗ EPSS Data ↗
bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=1268256 security.opensuse.org: https://security.opensuse.org/2026/07/15/selinux-seunshare.html

Credits

Matthias Gerstner of SUSE