Security Advisory

CVE-2026-6842

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-22 07:34:26
Last updated 2026-04-22 13:07:57
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.