CVE-2026-8784

Source
https://cve.org/CVERecord?id=CVE-2026-8784
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8784.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8784
Published
2026-05-18T02:30:13.275Z
Modified
2026-08-12T16:09:28.054537Z
Severity
  • 1.8 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
npitre cramfs-tools cramfsck.c change_file_status symlink
Details

A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function changefilestatus of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.

Database specific
{
    "cwe_ids": [
        "CWE-59",
        "CWE-61"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8784.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/npitre/cramfs-tools

Affected ranges

Type
GIT
Repo
https://github.com/npitre/cramfs-tools
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "2.1"
        },
        {
            "last_affected": "2.1"
        },
        {
            "introduced": "2.2"
        },
        {
            "last_affected": "2.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.1
2.2
v2.*
v2.0
v2.1
v2.2

Database specific

vanir_signatures
[
    {
        "target": {
            "function": "change_file_status",
            "file": "cramfsck.c"
        },
        "id": "CVE-2026-8784-0ef643f7",
        "signature_type": "Function",
        "digest": {
            "function_hash": "40044488469052910009332236318243580162",
            "length": 573.0
        },
        "signature_version": "v1",
        "source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
        "deprecated": false
    },
    {
        "target": {
            "file": "cramfsck.c"
        },
        "id": "CVE-2026-8784-1419b285",
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "321440437538111247303453851360562575517",
                "302212829327094417954707581520971874255",
                "177023179342980576771244919190948280823",
                "200739404057838626650709198309193450643",
                "140175060704430441862739947271083198762",
                "68717702535936958111812792909189418446",
                "196629797155371159077270066834493302920",
                "114380981663144152342277663209428007884",
                "65314385269834882525140852634132133764",
                "249285101829246671317305932649077545407",
                "292563785636244222747923183048379972537",
                "203965405301715087189221832477395209286",
                "114435104768797533779637141615305720763",
                "262326733068638690467206186392342268111",
                "100623091388501703536571517666062701359",
                "326975894786582081100118506177899291378",
                "48787732901192859040940806240232159132",
                "11483456411337640837026884389890026655",
                "32941504264965204766098718151095758507",
                "170597014779488904360717484966735312613",
                "199522071654014807690140616528072849465",
                "71758906890559691091462213647044373226",
                "233077418682054661779514961297071213225",
                "285913193413690440911224690222864896039",
                "237799326724055330573824687963955717758",
                "150558962512277297021586667170444896408",
                "282053592102837931542982291508180045278",
                "160862180061832448894984881680537228504",
                "35967297510075340470045440209545328579",
                "242632058432149191397998843001132307752",
                "63060197903003882658894479934014271021",
                "196260555363254851758306136328128930755",
                "110109321919148324411996254907335773563",
                "40062066242663278948612832231958909701",
                "256340440501160895180580264199200904050",
                "11040260598439082899724246594172595255",
                "102902984756368774634858368204177306065",
                "314347728697058253154040287090600650143",
                "227873881412926585236247316298949108653",
                "64532137672748543109270168754940114485",
                "2478837315733749900781848260574210910"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
        "deprecated": false
    },
    {
        "target": {
            "function": "die",
            "file": "cramfsck.c"
        },
        "id": "CVE-2026-8784-d1a78ac9",
        "signature_type": "Function",
        "digest": {
            "function_hash": "39294100263484989869914382135671155206",
            "length": 464.0
        },
        "signature_version": "v1",
        "source": "https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-12T16:09:28Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8784.json"