A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function changefilestatus of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.
{
"cwe_ids": [
"CWE-59",
"CWE-61"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8784.json",
"cna_assigner": "VulDB"
}{
"extracted_events": [
{
"introduced": "2.0"
},
{
"last_affected": "2.0"
},
{
"introduced": "2.1"
},
{
"last_affected": "2.1"
},
{
"introduced": "2.2"
},
{
"last_affected": "2.2"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
[
{
"target": {
"function": "change_file_status",
"file": "cramfsck.c"
},
"id": "CVE-2026-8784-0ef643f7",
"signature_type": "Function",
"digest": {
"function_hash": "40044488469052910009332236318243580162",
"length": 573.0
},
"signature_version": "v1",
"source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
"deprecated": false
},
{
"target": {
"file": "cramfsck.c"
},
"id": "CVE-2026-8784-1419b285",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321440437538111247303453851360562575517",
"302212829327094417954707581520971874255",
"177023179342980576771244919190948280823",
"200739404057838626650709198309193450643",
"140175060704430441862739947271083198762",
"68717702535936958111812792909189418446",
"196629797155371159077270066834493302920",
"114380981663144152342277663209428007884",
"65314385269834882525140852634132133764",
"249285101829246671317305932649077545407",
"292563785636244222747923183048379972537",
"203965405301715087189221832477395209286",
"114435104768797533779637141615305720763",
"262326733068638690467206186392342268111",
"100623091388501703536571517666062701359",
"326975894786582081100118506177899291378",
"48787732901192859040940806240232159132",
"11483456411337640837026884389890026655",
"32941504264965204766098718151095758507",
"170597014779488904360717484966735312613",
"199522071654014807690140616528072849465",
"71758906890559691091462213647044373226",
"233077418682054661779514961297071213225",
"285913193413690440911224690222864896039",
"237799326724055330573824687963955717758",
"150558962512277297021586667170444896408",
"282053592102837931542982291508180045278",
"160862180061832448894984881680537228504",
"35967297510075340470045440209545328579",
"242632058432149191397998843001132307752",
"63060197903003882658894479934014271021",
"196260555363254851758306136328128930755",
"110109321919148324411996254907335773563",
"40062066242663278948612832231958909701",
"256340440501160895180580264199200904050",
"11040260598439082899724246594172595255",
"102902984756368774634858368204177306065",
"314347728697058253154040287090600650143",
"227873881412926585236247316298949108653",
"64532137672748543109270168754940114485",
"2478837315733749900781848260574210910"
]
},
"signature_version": "v1",
"source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
"deprecated": false
},
{
"target": {
"function": "die",
"file": "cramfsck.c"
},
"id": "CVE-2026-8784-d1a78ac9",
"signature_type": "Function",
"digest": {
"function_hash": "39294100263484989869914382135671155206",
"length": 464.0
},
"signature_version": "v1",
"source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
"deprecated": false
}
]
"2026-08-12T16:09:28Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8784.json"