{"id":"AZL-97011","summary":"CVE-2026-47187 affecting package fuse-sshfs 3.7.3-1","details":"SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel against the local filesystem. The documented transform_symlinks mitigation does not contain relative targets because transform_symlink() returns early at sshfs.c:2181, while sshfs_readlink() at sshfs.c:2234 to sshfs.c:2236 otherwise copies the server-supplied link target to the kernel. A victim or victim-side tool that follows such a link through ordinary operations such as cp, rsync, backup tooling, or an editor can disclose readable local files back to the server or write server-controlled content to writable local files, potentially including startup or scheduled-task files. This issue is fixed in version 3.7.6.","modified":"2026-08-30T05:24:52Z","published":"2026-08-19T15:17:05Z","upstream":["CVE-2026-47187"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47187"}],"affected":[{"package":{"name":"fuse-sshfs","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/fuse-sshfs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.7.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97011.json"}}],"schema_version":"1.9.0"}