CVE-2026-8784 Details
Description
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.
A vulnerability in npitre cramfs-tools versions through 2.2 allows for symlink following during the extraction of cramfs images. This issue arises in the 'cramfsck' utility when it is run with the continue-on-error option, and the extraction directory is a symlink. The 'change_file_status' function in 'cramfsck.c' is affected, leading to potential unauthorized file writes in the user's home directory.
Users are advised to update to the latest version of npitre cramfs-tools, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 18, 2026CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/npitre/cramfs-tools/ | [email protected] | Source CodeVendor |
| https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f | [email protected] | Source CodeVendor |
| https://github.com/npitre/cramfs-tools/issues/13 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/811897 | [email protected] | Permission Required |
| https://vuldb.com/vuln/364408 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/364408/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| npitre cramfs-tools | <= 2.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | New CVE Received | [email protected] |
Volerion