PT-2026-51023 · Lima · Lima

CVE-2026-53657

·

Published

2026-06-19

·

Updated

2026-09-04

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lima versions prior to 2.1.3
Description On Lima instances using the qemu driver with the guest agent enabled, a local unprivileged user within the virtual machine can achieve root privileges. The issue stems from the guest agent socket /run/lima-guestagent.sock being world-writable (permissions 0o777) and owned by root. An attacker can connect to this socket to access a gRPC API without authentication and utilize the Tunnel RPC function. This function allows the agent to open connections to arbitrary addresses, including Unix socket addresses of privileged daemons such as D-Bus, effectively allowing the attacker to execute commands as root within the VM.
Recommendations Update Lima to version 2.1.3 or later. As a temporary mitigation, restrict access to the /run/lima-guestagent.sock socket to prevent unprivileged users from interacting with the guest agent.

Exploit

Fix

LPE

Exposure of Resource to Wrong Sphere

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53657
GHSA-2J9V-P4XJ-CJW2
GO-2026-6230
OPENSUSE-SU-2026:21761-1

Affected Products

Lima