Open Source Security mailing list@oss_securityDisclosure
A TOCTOU race condition in GNU sed's --follow-symlinks option was disclosed and fixed in version 4.10.
kiran ghimire@cimihan1945General
The user shares a learning experience on CVE-2026-5958 via cveplayground.com, indicating a walk-through but providing no exploit details, patches, or technical depth.
afine@afinePLDisclosure
The text discloses a TOCTOU race condition in GNU sed 4.1e‑4.9 and explains how an attacker can exploit it by swapping a symlink during sed’s "-i" operation with "--follow-symlinks".
CVE@CVEnewDisclosure
The excerpt provides a concise technical note on CVE-2026-5958, highlighting a race condition in sed, but contains no PoC, exploit, patch, or active exploitation information.
Ferramentas Linux@Cezar_H_LinuxDisclosure
A new GNU Sed TOCTOU vulnerability (CVE-2026-5958) that permits arbitrary file overwrite has been disclosed, with a link for further details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces the CVE‑2026‑5958 vulnerability, describing a race condition that allows arbitrary file overwrite via symlink following in GNU sed, without mentioning PoC, exploit code, or patches.
Infoflowcloud@infoflowcloudDisclosure
The notice discloses CVE-2026-5958, detailing a non-atomic filesystem operation issue in sed when using -i and --follow-symlinks; no PoC, exploit, patch, or active exploitation is mentioned.