Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94145.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94145
Upstream
Published
2026-07-29T17:16:52Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-52791 affecting package fuse-overlayfs 1.14-1
Details

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.

References

Affected packages

Azure Linux:3 / fuse-overlayfs

Package

Name
fuse-overlayfs
Purl
pkg:rpm/azure-linux/fuse-overlayfs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.14-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94145.json"