CyberICT

CVE-2025-68146

Microsoft · Published January 3, 2026

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

filelock has TOCTOU race condition that allows symlink attacks during lock file creation. filelock has TOCTOU race condition that allows symlink attacks during lock file creation

Affected Products

  • azl3 python-filelock 3.14.0-1 on Azure Linux 3.0
  • cbl2 python-filelock 3.0.12-13 on CBL Mariner 2.0
  • cbl2 python-filelock 3.0.12-13

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:P