VYPR

LiME

by Jtsylve

CVEs (1)

  • CVE-2026-85092MedSep 3, 2026
    risk 0.43cvss 6.6epss

    LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can…