{"id":"CVE-2026-49421","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-49421","summary":"The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup.  The flag was silently…","details":"The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup.  The flag was silently dropped, so path resolution was not actually restricted.\n\nA process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to confine path resolution can in fact resolve paths above the starting directory.  A caller relying on this flag for path containment may delete files outside the intended directory tree.","published":"2026-08-19T06:17:41.160","modified":"2026-08-26T18:16:35.190","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:42.unlinkat.asc"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T18:16:35.190"}}