EIP-2026-102729

PRE-CVE

RedHat Linux - Stickiness of /tmp

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102729. PoCs published by Tavis Ormandy.

AI-analyzed exploit summary This advisory describes a vulnerability in Red Hat's seunshare utility, which allows unprivileged users to bypass the sticky bit on /tmp by mounting a new directory, potentially leading to privilege escalation or system damage. The example demonstrates how an attacker can manipulate temporary files used by setuid applications like ksu.

Description

RedHat Linux - Stickiness of /tmp

Exploits (1)

exploitdb WRITEUP VERIFIED
by Tavis Ormandy · textdoslinux
https://www.exploit-db.com/exploits/16216

This advisory describes a vulnerability in Red Hat's seunshare utility, which allows unprivileged users to bypass the sticky bit on /tmp by mounting a new directory, potentially leading to privilege escalation or system damage. The example demonstrates how an attacker can manipulate temporary files used by setuid applications like ksu.

Classification
Writeup 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: policycore-utils (seunshare) on Red Hat Enterprise Linux and Fedora
No auth needed
Prerequisites: Access to a system with seunshare installed · Ability to execute seunshare
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026