From 4724d7f8c3393ec1f048c93933e6e3e6ec321f0e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bern=C3=A1t=20G=C3=A1bor?= Date: Mon, 15 Dec 2025 15:52:12 -0800 Subject: [PATCH] Fix TOCTOU symlink vulnerability in lock file creation (#461) CVE: CVE-2025-68146 Upstream: https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e [thomas: Dropped the windows part of the patch] Signed-off-by: Thomas Perale --- src/filelock/_unix.py | 2 +- src/filelock/_windows.py | 38 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 39 insertions(+), 1 deletion(-) diff --git a/src/filelock/_unix.py b/src/filelock/_unix.py index b2fd0f33..25cbeca6 100644 --- a/src/filelock/_unix.py +++ b/src/filelock/_unix.py @@ -38,7 +38,7 @@ class UnixFileLock(BaseFileLock): def _acquire(self) -> None: ensure_directory_exists(self.lock_file) - open_flags = os.O_RDWR | os.O_TRUNC + open_flags = os.O_RDWR | os.O_TRUNC | os.O_NOFOLLOW if not Path(self.lock_file).exists(): open_flags |= os.O_CREAT fd = os.open(self.lock_file, open_flags, self._context.mode)