An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like:
* gain access to possible private information found in /var/lib/pcrlock.d
* manipulate the data backed up in /tmp/pcrlock.d.bak, therefore violating the integrity of the data should it be restored.
* overwrite protected system files with data from /var/lib/pcrlock.d by placing symlinks to existing files in the directory tree in /tmp/pcrlock.d.bak.
This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1258241 |
|
History
Wed, 25 Feb 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found in /var/lib/pcrlock.d * manipulate the data backed up in /tmp/pcrlock.d.bak, therefore violating the integrity of the data should it be restored. * overwrite protected system files with data from /var/lib/pcrlock.d by placing symlinks to existing files in the directory tree in /tmp/pcrlock.d.bak. This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca. | |
| Weaknesses | CWE-377 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-25T10:59:58.372Z
Reserved: 2026-02-05T15:37:24.183Z
Link: CVE-2026-25701
No data.
Status : Received
Published: 2026-02-25T12:16:17.763
Modified: 2026-02-25T12:16:17.763
Link: CVE-2026-25701
No data.
OpenCVE Enrichment
No data.