{"id":"AZL-94145","summary":"CVE-2026-52791 affecting package fuse-overlayfs 1.14-1","details":"fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.","modified":"2026-08-29T05:25:22Z","published":"2026-07-29T17:16:52Z","upstream":["CVE-2026-52791"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52791"}],"affected":[{"package":{"name":"fuse-overlayfs","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/fuse-overlayfs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.14-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94145.json"}}],"schema_version":"1.9.0"}