This is a detailed technical writeup discussing a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability in Firejail's `--get` and `--put` functionality, which could lead to local privilege escalation. The advisory includes code snippets and explains how the vulnerability was fixed in a specific commit.
Classification
Writeup 95%
Target:
Firejail (version not specified, fixed in commit e152e2d)
No auth needed
Prerequisites:
Local access to the system · Firejail installed and vulnerable version in use