<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Pop!_OS</title>
  <link>https://cvedaily.com/pages/tags/pop-os.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/pop-os.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Pop!_OS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-25704 – A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25704</guid>
    <pubDate>Mon, 30 Mar 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25704</strong></p>
  <p>A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic.     This issue affects cosmic-greeter before https://github.Com/pop-os/cosmic-greeter/pull/426.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-271</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25704">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
