What is CVE-2026-52791?
CVE-2026-52791 was discovered in fuse-overlayfs, used for rootless containers. In the release-1.x C branch before version 1.17, SUID and SGID mode bits are preserved during open(O_TRUNC) and truncate operations on a copied-up file, allowing a low-privileged process to leave the upper-layer file with dangerous mode bits. Affected users should upgrade to version 1.17 or later immediately.
Azərbaycanca: CVE-2026-52791, rootless konteynerlər üçün istifadə olunan fuse-overlayfs-də aşkar edilib. 1.17 versiyasından əvvəlki “release-1.x C” branch-də, copied-up fayllar üzərində open(O_TRUNC) və truncate əməliyyatları zamanı SUID/SGID bit-ləri qorunur, bu da aşağı imtiyazlı prosesə yuxarı təbəqədəki faylı təhlükəli rejim bit-ləri ilə saxlamağa imkan verir. Təsirə məruz qalan istifadəçilər dərhal 1.17 və ya daha yeni versiyaya yeniləməlidirlər.
FAQ2
Which users are affected by CVE-2026-52791?
Users of the release-1.x C branch of fuse-overlayfs before version 1.17 are affected by CVE-2026-52791.
What action should be taken to remediate CVE-2026-52791?
Affected users should immediately upgrade fuse-overlayfs to version 1.17 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.