PT-2026-41632 · Unknown · Cramfs-Tools

Nich0Las

·

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-8784

CVSS v3.1

4.2

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions npitre cramfs-tools versions prior to 2.3
Description A local issue exists in the change file status() function within the cramfsck.c file. A manipulation of this function allows for symlink following, which occurs when a program follows a symbolic link to a target file, potentially allowing access to unauthorized files.
Recommendations Apply the patch b4a3a695c9873f824907bd15659f2a6ac7667b4f to resolve the issue. As a temporary workaround, restrict access to the change file status() function in cramfsck.c to minimize the risk of exploitation.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-8784

Affected Products

Cramfs-Tools