Skip to content

os: Root.Chmod can follow symlinks out of the root on Linux #78293

Description

@neild

On Linux, if the target of Root.Chmod is replaced with a symlink while
the chmod operation is in progress, Chmod could operate on the target
of the symlink, even when the target lies outside the root.
 
The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag,
which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its
target before acting and returns an error if the target is a symlink
lying outside the root, so the impact is limited to cases where the
target is replaced with a symlink between the check and operation.
 
On Linux, Root.Chmod now uses the fchmodat2 syscall when available, and
an workaround using /proc/self/fd otherwise.
 
Thanks to Uuganbayar Lkhamsuren for reporting this issue.
 
This is CVE-2026-32282 and Go issue #78293.


This is a PRIVATE issue for CVE-2026-32282, tracked in http://b/493187489 and fixed by https://go-internal-review.git.corp.google.com/c/go/+/3900.

cc @golang/security and @golang/release

Activity

  1. added this to the Go1.27 milestone on Mar 23, 2026
  2. self-assigned this
    on Mar 23, 2026
  3. neild commented on Mar 27, 2026

    @neild
    ContributorAuthor

    @gopherbot please open backport issues for this security fix

  4. gopherbot commented on Mar 27, 2026

    @gopherbot
    Contributor

    Backport issue(s) opened: #78425 (for 1.25), #78426 (for 1.26).

    Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.

  5. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763542 mentions this issue: [release-branch.go1.26] internal/syscall/unix: properly support AT_SYMLINK_NOFOLLOW on Linux

  6. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763550 mentions this issue: [release-branch.go1.25] internal/syscall/unix: properly support AT_SYMLINK_NOFOLLOW on Linux

  7. added 2 commits that reference this issue on Apr 7, 2026
    4c79c42
    b6176f4
  8. changed the title [-]security: fix CVE-2026-32282[/-] [+]crypto/x509: incorrect enforcement of email constraints[/+] on Apr 7, 2026
  9. changed the title [-]crypto/x509: incorrect enforcement of email constraints[/-] [+]os: Root.Chmod can follow symlinks out of the root on Linux[/+] on Apr 7, 2026
  10. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763761 mentions this issue: internal/syscall/unix: properly support AT_SYMLINK_NOFOLLOW on Linux

  11. lzap commented on May 11, 2026

    @lzap

    Do I understand this correctly that the only affected versions are 1.25/1.26? Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions