PT-2026-65846 · Unknown · Fuse-Overlayfs

CVE-2026-52791

·

Published

2026-07-29

·

Updated

2026-09-03

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions fuse-overlayfs versions prior to 1.17
Description In the release-1.x C branch, the software preserves SUID (Set User ID) and SGID (Set Group ID) mode bits in the main.c file during open(O TRUNC) and truncate handling on a copied-up file. This behavior allows a low-privileged process to leave the upper-layer file with mode 4777, potentially leading to privilege escalation.
Recommendations Update to version 1.17.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94145
CVE-2026-52791
GHSA-2CC4-P72C-V85H
OPENSUSE-SU-2026:11461-1
OPENSUSE-SU-2026:21753-1
SUSE-SU-2026:23252-1

Affected Products

Fuse-Overlayfs