CVE-2026-54778MEDIUMCVSS 6.2

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

Published Jun 19, 2026·Updated Jun 19, 2026

Description

### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.

Affected Packages (1)

CoreWCF.UnixDomainSocketNUGET
Fixed in 1.8.1

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free