{"id":"CVE-2025-41259","summary":"SWUpdate Untrusted Script Execution via Signed Update TOCTOU","details":"SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.","modified":"2026-08-12T11:28:52.867747Z","published":"2026-06-03T11:01:59.871Z","database_specific":{"cna_assigner":"sba-research","cwe_ids":["CWE-367"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41259.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41259.json"},{"type":"ADVISORY","url":"https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251206-01_SWUpdate_Untrusted_Script_Execution_via_Signed_Update_TOCTOU"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-41259"},{"type":"FIX","url":"https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d"},{"type":"PACKAGE","url":"https://github.com/sbabic/swupdate"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sbabic/swupdate","events":[{"introduced":"0"},{"fixed":"602edf8e57f940791034096c9e24206097b4b7a6"},{"fixed":"f4bd64260e233e207354d68d572b1cbc3e63689d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2026.05"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["2025.12","2025.05","2024.12","2024.05.2","2024.05","2023.12.1","2023.12","2023.05","2022.12","2022.05","2021.11","2021.04","2020.11","2020.04","2020.04-rc2","2020.04-rc1","2019.11","2019.11-rc1","2019.04","2019.04-rc1","2018.11","2018.11-rc1","2018.03","2018.03-rc1","2017.11","2017.07","2017.07-rc1","2017.04","2017.04-rc2","2017.04-rc1","2017.01","2017.01-rc1","2016.10","2016.10-rc1","2016.07","2016.07-rc3","2016.04","2016.04-rc1","2015.07","2014.07"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-41259.json","vanir_signatures_modified":"2026-08-12T11:28:52Z","vanir_signatures":[{"target":{"file":"core/util.c","function":"swupdate_remove_directory"},"deprecated":false,"digest":{"function_hash":"89529434304315812385780302496230342401","length":634},"id":"CVE-2025-41259-39501b54","signature_type":"Function","signature_version":"v1","source":"https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/sbabic/swupdate/commit/f4bd64260e233e207354d68d572b1cbc3e63689d","target":{"file":"core/util.c"},"deprecated":false,"digest":{"line_hashes":["244392430412439603036487102069731633187","173388438307855236941269846073740091773","12652183546458038736969437918408029488","275813714068425932503340476201464589050","301037403177265941945846514348303833616","114917503296895387442606474211509284792","120594897682487706085760629067832957018","88348980539232767229855587301500979699","138257688947722297478605601658938613096"],"threshold":0.9},"id":"CVE-2025-41259-ed94379b"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}