Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fuse | Jul 30, 2024 | Sep 2, 2011 |
| Oracle_linux | — | Upgrade fuse-develUpgrade fuse-libsUpgrade fuse | Oct 16, 2024 | Sep 2, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 2, 2010 |
| Suse | — | Upgrade libblkid-devel-32bitUpgrade libblkid-develUpgrade fuse-develUpgrade fuse-devel-staticUpgrade libuuid-devel-32bitUpgrade libfuse2-32bitUpgrade libfuse2Upgrade uuiddUpgrade fuseUpgrade libuuid-develUpgrade libblkid1Upgrade libuuid1-32bitUpgrade libblkid1-32bitUpgrade libuuid1Upgrade util-linux-langUpgrade util-linux | Feb 17, 2015 | Sep 2, 2011 |
| Ubuntu | — | Upgrade fuse-utils | Nov 8, 2024 | Sep 2, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub