CVE-2026-32282

EUVD-2026-20012
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
< 1.25.9
golanggo
1.26.0 ≤
𝑥
< 1.26.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
postponed
golang-1.19
bookworm
no-dsa
golang-1.24
trixie
no-dsa
golang-1.25
forky
1.25.10-1
fixed
sid
1.25.10-2
fixed
golang-1.26
forky
1.26.3-1
fixed
sid
1.26.3-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
questing
dne
resolute
dne
golang-1.6
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
golang-1.17
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
questing
needs-triage
resolute
needs-triage
golang-1.24
jammy
needs-triage
noble
needs-triage
questing
needs-triage
resolute
needs-triage
golang-1.25
jammy
dne
noble
dne
questing
needs-triage
resolute
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
git-lfs
RHEL 9
0:3.7.1-4.el9_8
fixed
go-toolset
RHEL 9
0:1.25.9-1.el9_7
fixed
golang
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-bin
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-docs
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-misc
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-race
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-src
RHEL 9
0:1.25.9-1.el9_7
fixed
golang-tests
RHEL 9
0:1.25.9-1.el9_7
fixed
grafana
RHEL 8
0:9.2.10-30.el8_10
fixed
RHEL 9
0:10.2.6-22.el9_8
fixed
grafana-pcp
RHEL 9
0:5.1.1-15.el9_8
fixed
grafana-selinux
RHEL 8
0:9.2.10-30.el8_10
fixed
RHEL 9
0:10.2.6-22.el9_8
fixed
opentelemetry-collector
RHEL 9
0:0.144.0-2.el9_8
fixed
rhc
RHEL 9
1:0.2.7-6.el9_8
fixed
rhc-devel
RHEL 9
1:0.2.7-6.el9_8
fixed