Low severityNVD Advisory· Published Jul 29, 2026· Updated Sep 10, 2026
CVE-2026-52791
CVE-2026-52791
Description
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/fuse-overlayfs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/fuse-overlayfs&distro=openSUSE%20Tumbleweed
< 1.15-160000.3.1+ 1 more
- (no CPE)range: < 1.15-160000.3.1
- (no CPE)range: < 1.17-1.1
- Range: <1.17
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.