CVE-2026-40556 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
A vulnerability exists in GNU nano versions 2.9.1 prior to 9.0, where the application creates the user's ~/.local directory with overly permissive permissions. When the directory is first created for Cross-Desktop Group (XDG) data storage, nano sets the permissions to 0777, making it world-writable. This issue is particularly problematic in environments with a relaxed or zero umask, such as container environments, CI/CD runners, embedded systems, or user shells with umask 000. In these cases, the ~/.local directory becomes world-writable, allowing local attackers to exploit a race condition between the creation of the ~/.local directory and its subdirectories. This exploitation can lead to unauthorized files being written into the victim's XDG directory hierarchy.
Users can upgrade to GNU nano version 9.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Apr 29, 2026 | CVE Rejected | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |