### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.
Update CoreWCF.UnixDomainSocket to 1.8.1; CoreWCF.UnixDomainSocket to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution affects CoreWCF.UnixDomainSocket (nuget), CoreWCF.UnixDomainSocket (nuget). Severity is medium. ### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.UnixDomainSocketnuget | <1.8.1 |
### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.
Update CoreWCF.UnixDomainSocket to 1.8.1; CoreWCF.UnixDomainSocket to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution affects CoreWCF.UnixDomainSocket (nuget), CoreWCF.UnixDomainSocket (nuget). Severity is medium. ### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.UnixDomainSocketnuget | <1.8.1 |
| 1.8.1 |
| CoreWCF.UnixDomainSocketnuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 1.8.1 |
| CoreWCF.UnixDomainSocketnuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard