FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fuse | Jul 30, 2024 | Jan 22, 2011 |
| Oracle_linux | — | Upgrade fuse-libsUpgrade fuseUpgrade fuse-devel | Oct 16, 2024 | Jan 22, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 2, 2010 |
| Suse | — | Upgrade libfuse2-32bitUpgrade libfuse2Upgrade libuuid1Upgrade libuuid-develUpgrade libblkid-develUpgrade uuiddUpgrade fuse-develUpgrade libblkid-devel-32bitUpgrade libuuid-devel-32bitUpgrade libuuid1-32bitUpgrade fuse-devel-staticUpgrade libblkid1-32bitUpgrade util-linux-langUpgrade libblkid1Upgrade fuseUpgrade util-linux | Feb 17, 2015 | Jan 22, 2011 |
| Ubuntu | — | Upgrade fuse-utilsUpgrade mount | Nov 8, 2024 | Jan 22, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub