๐Ÿ” CVE Alert

CVE-2026-52791

UNKNOWN 0.0

fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.

CWE CWE-266
Vendor containers
Product fuse-overlayfs
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for containers fuse-overlayfs

Be the first to know when new unknown vulnerabilities affecting containers fuse-overlayfs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

containers / fuse-overlayfs
< 1.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h github.com: https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f github.com: https://github.com/containers/fuse-overlayfs/releases/tag/v1.17