PT-2026-65846 · Unknown · Fuse-Overlayfs
CVE-2026-52791
·
Published
2026-07-29
·
Updated
2026-09-03
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
fuse-overlayfs versions prior to 1.17
Description
In the release-1.x C branch, the software preserves SUID (Set User ID) and SGID (Set Group ID) mode bits in the
main.c file during open(O TRUNC) and truncate handling on a copied-up file. This behavior allows a low-privileged process to leave the upper-layer file with mode 4777, potentially leading to privilege escalation.Recommendations
Update to version 1.17.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuse-Overlayfs