CVE-2026-41051
published 2026-05-13CVE-2026-41051: csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
PriorityP417medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.07%
0.1th percentile
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | opensuse_tumbleweed | >= ? < 2.0+git.1600444747.83b3644-3.1 | 2.0+git.1600444747.83b3644-3.1 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SUSE openSUSE Tumbleweed prior 2.0+git.1600444747.83b3644-3.1 csync2 toctou (Nessus ID 315100)
vuldb·2026-05-17·CVSS 5.1
CVE-2026-41051 [MEDIUM] SUSE openSUSE Tumbleweed prior 2.0+git.1600444747.83b3644-3.1 csync2 toctou (Nessus ID 315100)
A vulnerability marked as problematic has been reported in SUSE openSUSE Tumbleweed. Affected by this issue is some unknown functionality of the component csync2. Performing a manipulation results in time-of-check time-of-use.
This vulnerability is reported as CVE-2026-41051. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-7mqw-hr29-pj76: csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories
ghsa_unreviewed·2026-05-13
CVE-2026-41051 [MEDIUM] CWE-367 GHSA-7mqw-hr29-pj76: csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published