CVE-2026-3836
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
A local, unprivileged attacker can exploit a path traversal flaw in the D-Bus locale configuration, crashing dnf5daemon-server via a crafted string. This can lead to a DoS with a core dump.
Description source: VulnCheck
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 31, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||