Several security issues were fixed in Filelock.. ========================================================================== Ubuntu Security Notice USN-7999-1 February 02, 2026 python-filelock vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Filelock. Software Description: - python-filelock: A platform-independent file lock for Python Details: It was discovered that Filelock incorrectly handled symlinks in temp files. A local attacker could possibly use this issue to cause lock operations to fail or behave unexpectedly. (CVE-2026-22701) It was discovered that the file locking implementation in the Filelock package contained a race condition. A local attacker could possibly use this to cause a denial of service or corrupt arbitrary user files. (CVE-2025-68146) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-filelock 3.13.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-filelock 3.6.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-filelock 3.0.12-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7999-1 CVE-2025-68146, CVE-2026-22701 . Several security issues were fixed in Filelock affecting multiple Ubuntu LTS releases.Critical updates are recommended.. python-filelock update, Ubuntu security, file locking issues, Denial of Service, local attacker. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for python-filelock Announcement ID: SUSE-SU-2026:0335-1 Release Date: 2026-01-29T10:15:43Z Rating: moderate References: * bsc#1256457 Cross-References: * CVE-2026-22701 CVSS scores: * CVE-2026-22701 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-22701 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22701 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-filelock fixes the following issues: * CVE-2026-22701: Fixed TOCTOU race condition in SoftFileLock implementation of he filelock package (bsc#1256457) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-335=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-335=1 ## Package List: * Development Tools Module 15-SP7 (noarch) * python3-filelock-3.0.12-150100.3.9.1 * SUSE Package Hub 15 15-SP7 (noarch) * python3-filelock-3.0.12-150100.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22701.html * https://bugzilla.suse.com/show_bug.cgi?id=1256457 . SUSE security update for python-filelock addresses a moderate risk TOCTOU race condition vulnerability. Apply patch now.. python-filelock update, SUSE security patch, TOCTOU race condition,moderate security risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.