LOW 2.0 NVD
CVE-2026-52791
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in m
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.
References
- https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad72
- https://github.com/containers/fuse-overlayfs/releases/tag/v1.17
- https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
- https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
This low severity vulnerability with a CVSS score of 2.0 was published on 2026-07-29 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.