Time-of-check Time-of-use (TOCTOU) Race Condition in filelock - CVE-2026-22701
Published: January 13, 2026
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to a race condition in the SoftFileLock implementation of the filelock package. A local user can create a symbolic link to a critical file on the system between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Package Hub 15
Development Tools Module
Ubuntu
Anolis OS
openEuler
Netezza Appliance
watsonx Code Assistant On Prem
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
Maximo Application Suite Ai Service
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Robotic Process Automation for Cloud Pak
IBM Watson Discovery for IBM Cloud Pak for Data
python-filelock (Ubuntu package)
python3-filelock
python3-filelock-doc
python-filelock-doc
python-filelock-help
python-filelock
How to mitigate CVE-2026-22701
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.28, 8.11.26, 9.0.18, 9.1.8
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.27, 9.0.19, 9.1.9
Maximo Application Suite Ai Service - update to 9.1.13
python-filelock (Ubuntu package) - addressed in versions 3.0.4-1ubuntu0.1~esm1, 3.0.12-2ubuntu0.1~esm1, 3.6.0-1ubuntu0.1~esm1, 3.13.1-1ubuntu0.1~esm1
python3-filelock - update to 3.0.12-150100.3.9.1
python3-filelock-doc - update to 3.13.0-2
python3-filelock - update to 3.13.0-2
python-filelock-doc - update to 3.13.1-4
python3-filelock - update to 3.13.1-4
python-filelock-help - update to 3.13.1-4
python-filelock - update to 3.13.1-4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
watsonx Assistant Cartridge - update to 5.4
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
External References
Related Security Bulletins
- Local denial of service in filelock
- openEuler 24.03 LTS SP1 update for python-filelock
- openEuler 24.03 LTS update for python-filelock
- openEuler 24.03 LTS SP3 update for python-filelock
- openEuler 24.03 LTS SP2 update for python-filelock
- Anolis OS update for python-filelock
- SUSE update for python-filelock
- Ubuntu update for python-filelock
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- IBM Edge Data Collector update for filelock
- Multiple vulnerabilities in IBM Maximo AI Service
- IBM Watson Discovery Cartridge update for filelock
- IBM Netezza Appliance update for filelock
- IBM Robotic Process Automation for Cloud Pak update for filelock
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for filelock