USN-7999-1: Filelock vulnerabilities
USN-7999-1: Filelock vulnerabilities
Publication date 2 February 2026
Overview: Several security issues were fixed in Filelock.
Packages
python-filelock - A platform-independent file lock for Python
Details
It was discovered that Filelock incorrectly handled symlinks in temp files.
A local attacker could possibly use this issue to cause lock operations to
fail or behave unexpectedly. (CVE-2026-22701)
It was discovered that the file locking implementation in the Filelock
package contained a race condition. A local attacker could possibly use
this to cause a denial of service or corrupt arbitrary user files.
(CVE-2025-68146)
Update instructions
The problem can be corrected by updating your system to the following package versions:
- 24.04 LTS noble python3-filelock – 3.13.1-1ubuntu0.1~esm1
- 22.04 LTS jammy python3-filelock – 3.6.0-1ubuntu0.1~esm1
- 20.04 LTS focal python3-filelock – 3.0.12-2ubuntu0.1~esm1
- 18.04 LTS bionic python-filelock – 3.0.4-1ubuntu0.1~esm1
- python3-filelock – 3.0.4-1ubuntu0.1~esm1

