Description
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
Problem types
CWE-367 Time-of-check time-of-use (TOCTOU) race condition
Product status
Any version before 2026.05
Credits
Reinhard Kugler (SBA Research)
References
github.com/...sted_Script_Execution_via_Signed_Update_TOCTOU
github.com/...sted_Script_Execution_via_Signed_Update_TOCTOU
github.com/...ommit/f4bd64260e233e207354d68d572b1cbc3e63689d
github.com/sbabic/swupdate