Two vulnerabilities in the SELinux userspace utility seunshare 3.10 were disclosed and assigned CVE-2026-59676 and CVE-2026-59677. The first flaw is a symlink race in rm_rf() caused by openat() being used without O_NOFOLLOW, allowing an unprivileged local user to delete arbitrary root-owned files under certain conditions when seunshare is installed setuid-root. The second flaw affects killall(), where combining --kill with a user-supplied -Z SELinux context can let an unconfined user kill root-owned processes running in an unconfined context.
Researchers said the default targeted SELinux policy leaves interactive users in an unconfined domain rather than transitioning them into seunshare_t, giving the bugs practical root-like impact despite SELinux enforcement. Upstream fixed both issues in SELinux userspace utilities 3.11, including commit 38f0a4d9a and removal of the vulnerable --kill functionality in commit 572db2fa. The file-deletion issue was reproduced on openSUSE Tumbleweed with policycoreutils 3.10, while Fedora 44 appeared to have a backported fix for that flaw; the process-kill issue was reproduced on both openSUSE and Fedora 44.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A follow-up on oss-sec announced CVE assignment for the two seunshare vulnerabilities affecting release 3.10. CVE-2026-59676 covers the rm_rf() local file deletion vector, and CVE-2026-59677 covers the killall() process-kill vector.
A security review disclosed two local denial-of-service attack vectors in the setuid-root SELinux userspace utility seunshare version 3.10: a symlink race in rm_rf() and a process-kill issue in killall(). The disclosure noted the flaws could have root-like impact on systems using the default targeted SELinux policy because seunshare runs in an unconfined domain.
The disclosure reported that upstream had fixed both seunshare issues in SELinux userspace utilities version 3.11. One fix was made in commit 38f0a4d9a, and the vulnerable --kill functionality was removed in commit 572db2fa.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcesecurity.opensuse.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.