rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Linuxcnc
Linuxcnc linuxcnc
Vendors & Products Linuxcnc
Linuxcnc linuxcnc

Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
Title SUID Root Privilege Escalation via Path Traversal in LinuxCNC rtapi_app

Tue, 30 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Description rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-30T13:04:39.190Z

Reserved: 2026-06-30T01:09:33.668Z

Link: CVE-2026-58302

cve-icon Vulnrichment

Updated: 2026-06-30T13:04:34.145Z

cve-icon NVD

Status : Deferred

Published: 2026-06-30T02:16:26.820

Modified: 2026-06-30T14:22:10.020

Link: CVE-2026-58302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:02:35Z

Weaknesses