{"id":"AZL-96609","summary":"CVE-2026-73585 affecting package sblim-cmpi-base 1.6.4-17","details":"A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.","modified":"2026-08-31T05:26:07Z","published":"2026-08-13T13:19:18Z","upstream":["CVE-2026-73585"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73585"}],"affected":[{"package":{"name":"sblim-cmpi-base","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/sblim-cmpi-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.6.4-17"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96609.json"}}],"schema_version":"1.9.0"}