{"id":"AZL-99993","summary":"CVE-2026-86469 affecting package glib 2.78.6-11","details":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","modified":"2026-09-14T17:34:05Z","published":"2026-09-07T16:17:30Z","upstream":["CVE-2026-86469"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469"}],"affected":[{"package":{"name":"glib","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/glib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.78.6-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99993.json"}}],"schema_version":"1.9.0"}