216.73.217.22

CVE-2026-8784

· Published 18/05/2026 04:16 · Modified 18/05/2026 19:22

Labels: CVE-2026-8784 2026-05-18CVE-2026-8784CWE-59[email protected]

Essential information

Published
18/05/2026 04:16
Modified
18/05/2026 19:22
Author
Creator
CVSS
1.8 LOW (v3) 1.8 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
npitre / cramfs-tools cpe:2.3:a:npitre:cramfs-tools:*:*:*:*:*:*:*:*

References