Skip to content

os: Root escape via symlink plus trailing slash (CVE-2026-39822) #79005

Description

@thatnealpatel

On Unix systems, opening a file in an os.Root improperly
followed symlinks to locations outside of the Root when
the final path component of the a path is a symbolic link
and the path ends in /.

For example, root.Open("symlink/") would open "symlink"
even when "symlink" is a symbolic link pointing outside of the root.

On Unix, openat(fd, path, O_NOFOLLOW) will follow symlinks
in path when path ends in a /. Root failed to account for
this behavior, permitting paths with a trailing / to escape.
It now properly sanitizes the path parameter provided to openat.

Thanks to Mundur (https://github.com/M0nd0R) for reporting this issue.

This is CVE-2026-39822 and Go issue https://go.dev/issue/79005.


This was a PRIVATE track issue, tracked in http://b/502195787.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    NeedsFixThe path to resolution is known, but the work has not been done.Securityrelease-blockervulncheck or vulndbIssues for the x/vuln or x/vulndb repo

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions