CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access. |
1Qualcomm 45Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+42 moreJun 17, 2026 Aug 6, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption while processing simultaneous requests via escape path. |
1Qualcomm 6Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSnapdragon 8 Gen 1 Mobile Platform Firmware+3 moreJun 17, 2026 Aug 6, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption when using Virtual cdm (Camera Data Mover) to write registers. |
1Qualcomm 29Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+26 moreJun 17, 2026 Aug 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while submitting blob data to kernel space though IOCTL. |
Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module. |
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalatio...Show more |
There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea i...Show more |
A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 25, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload. transport_{g2h,h2g} may become NULL after...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 25, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 22, 2025 N/A· v4 7.4 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_noti...Show more |
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 8, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Jul 8, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read() In the fts_read() function, when handling hwmon_pwm_auto_channels_temp, the code accesses the share...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 3, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_ps...Show more |
A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Gu...Show more |
PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of PEAK-System D...Show more |
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App'...Show more |