CVE-2026-8274 Details
Description
A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of the file cramfsck.c of the component Directory Handler. Such manipulation leads to path traversal. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version 2.2 is able to address this issue. The name of the patch is 2fc492747115b24d8a07eddd27a2d45229cb273c. Upgrading the affected component is recommended.
A path traversal vulnerability has been identified in npitre cramfs-tools versions through 2.1. The issue resides in the Directory Handler component, specifically within the do_directory function of cramfsck.c. This vulnerability allows for manipulation that could lead to unauthorized file writes outside the intended extraction directory. The exploitation can only be carried out in a local environment. The vulnerability has been publicly disclosed and can be exploited by crafting a specific cramfs image. Upgrading to version 2.2 addresses this issue.
Users are advised to upgrade to npitre cramfs-tools version 2.2, which includes the necessary fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/npitre/cramfs-tools/ | [email protected] | Source CodeVendor |
| https://github.com/npitre/cramfs-tools/commit/2fc492747115b24d8a07eddd27a2d45229cb273c | [email protected] | Source CodeVendor |
| https://github.com/npitre/cramfs-tools/issues/12 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/npitre/cramfs-tools/issues/12#issue-4307511739 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/npitre/cramfs-tools/releases/tag/v2.2 | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/810864 | [email protected] | Permission Required |
| https://vuldb.com/vuln/362571 | [email protected] | AdvisoryPermission RequiredRemedy |
| https://vuldb.com/vuln/362571/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| npitre cramfs-tools | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion