Debian Package Tracker
Register | Log in
Subscribe

cockpit-files

Cockpit component for file management

Choose email to subscribe with

general
  • source: cockpit-files (main)
  • version: 44-1
  • maintainer: Utopia Maintenance Team (archive) (DMD)
  • uploaders: Martin Pitt [DMD]
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable-bpo: 44-1~bpo13+1
  • testing: 44-1
  • unstable: 44-1
versioned links
  • 44-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 44-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • cockpit-files
action needed
Marked for autoremoval on 12 October due to sos, sphinxcontrib-log-cabinet: #1145981, #1147863 high
Version 44-1 of cockpit-files is marked for autoremoval from testing on Mon 12 Oct 2026. It depends (transitively) on sos, sphinxcontrib-log-cabinet, affected by #1145981, #1147863. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-12 Last update: 2026-09-22 14:31
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-91202: A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
  • CVE-2026-91203: A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
  • CVE-2026-91205: A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Created: 2026-09-19 Last update: 2026-09-20 03:31
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-91202: A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
  • CVE-2026-91203: A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
  • CVE-2026-91205: A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Created: 2026-09-19 Last update: 2026-09-20 03:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-08-30 10:34
news
[rss feed]
  • [2026-09-04] Accepted cockpit-files 44-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-09-04] cockpit-files 44-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-30] Accepted cockpit-files 44-1 (source) into unstable (Martin Pitt)
  • [2026-08-30] Accepted cockpit-files 43-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-08-05] cockpit-files 43-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-31] Accepted cockpit-files 43-1 (source) into unstable (Martin Pitt)
  • [2026-06-10] cockpit-files 41-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-05] Accepted cockpit-files 41-1 (source) into unstable (Martin Pitt)
  • [2026-06-03] cockpit-files 40-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-29] Accepted cockpit-files 40-1 (source) into unstable (Martin Pitt)
  • [2026-04-14] cockpit-files 39-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-09] Accepted cockpit-files 39-1 (source) into unstable (Martin Pitt)
  • [2026-03-24] cockpit-files 38-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-19] Accepted cockpit-files 38-1 (source) into unstable (Martin Pitt)
  • [2026-02-21] Accepted cockpit-files 36-1~bpo13+1 (source all) into stable-backports (Debian FTP Masters) (signed by: Martin Pitt)
  • [2026-02-19] cockpit-files 36-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-14] Accepted cockpit-files 36-1 (source all) into unstable (Debian FTP Masters) (signed by: Martin Pitt)
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 98)
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 44-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing