Bug 2508489 (CVE-2026-52791) - CVE-2026-52791 fuse-overlayfs: fuse-overlayfs: Privilege Escalation Vulnerability via SUID/SGID Bit Preservation
Summary: CVE-2026-52791 fuse-overlayfs: fuse-overlayfs: Privilege Escalation Vulnerabi...
Keywords:
Status: NEW
Alias: CVE-2026-52791
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509242 2509243 2509244
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 17:02 UTC by OSIDB Bzimport
Modified: 2026-07-30 10:46 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-29 17:02:11 UTC
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.


Note You need to log in before you can comment on or make changes to this bug.