CVE Explorer
CVE-2026-58302
rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"LinuxCNC","vendor":"LinuxCNC","versions":[{"lessThan":"2.9.9","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://bugs.debian.org/1140943"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/references/3
{"url":"https://github.com/LinuxCNC/linuxcnc/commit/00d534c87464a3ed446656998aa02b8abc74b391"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/references/0
{"url":"https://github.com/LinuxCNC/linuxcnc/commit/ea7cd579d39b586952a42e3da9a26d3e36e7a272"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/references/1
{"url":"https://github.com/LinuxCNC/linuxcnc/compare/v2.9.8...v2.9.9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4079fe5d05fa6bd854b0094687e0bd429165bc8df669d4d29dc8802b179d5c0d · sha256:14b414446ff51109… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.