{"id":"CVE-2026-8784","summary":"npitre cramfs-tools cramfsck.c change_file_status symlink","details":"A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.","modified":"2026-08-12T16:09:28.054537Z","published":"2026-05-18T02:30:13.275Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-59","CWE-61"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8784.json"},"references":[{"type":"WEB","url":"https://github.com/npitre/cramfs-tools/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8784.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8784"},{"type":"ADVISORY","url":"https://vuldb.com/submit/811897"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/364408"},{"type":"REPORT","url":"https://github.com/npitre/cramfs-tools/issues/13"},{"type":"REPORT","url":"https://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583"},{"type":"REPORT","url":"https://vuldb.com/vuln/364408/cti"},{"type":"FIX","url":"https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/npitre/cramfs-tools","events":[{"introduced":"5aea81001ac6c999175844080879f4024bf15fac"},{"fixed":"b4a3a695c9873f824907bd15659f2a6ac7667b4f"}],"database_specific":{"extracted_events":[{"introduced":"2.0"},{"last_affected":"2.0"},{"introduced":"2.1"},{"last_affected":"2.1"},{"introduced":"2.2"},{"last_affected":"2.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.0","2.1","2.2","v2.2","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8784.json","vanir_signatures_modified":"2026-08-12T16:09:28Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"40044488469052910009332236318243580162","length":573},"id":"CVE-2026-8784-0ef643f7","signature_type":"Function","signature_version":"v1","source":"https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f","target":{"file":"cramfsck.c","function":"change_file_status"}},{"signature_version":"v1","source":"https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f","target":{"file":"cramfsck.c"},"deprecated":false,"digest":{"line_hashes":["321440437538111247303453851360562575517","302212829327094417954707581520971874255","177023179342980576771244919190948280823","200739404057838626650709198309193450643","140175060704430441862739947271083198762","68717702535936958111812792909189418446","196629797155371159077270066834493302920","114380981663144152342277663209428007884","65314385269834882525140852634132133764","249285101829246671317305932649077545407","292563785636244222747923183048379972537","203965405301715087189221832477395209286","114435104768797533779637141615305720763","262326733068638690467206186392342268111","100623091388501703536571517666062701359","326975894786582081100118506177899291378","48787732901192859040940806240232159132","11483456411337640837026884389890026655","32941504264965204766098718151095758507","170597014779488904360717484966735312613","199522071654014807690140616528072849465","71758906890559691091462213647044373226","233077418682054661779514961297071213225","285913193413690440911224690222864896039","237799326724055330573824687963955717758","150558962512277297021586667170444896408","282053592102837931542982291508180045278","160862180061832448894984881680537228504","35967297510075340470045440209545328579","242632058432149191397998843001132307752","63060197903003882658894479934014271021","196260555363254851758306136328128930755","110109321919148324411996254907335773563","40062066242663278948612832231958909701","256340440501160895180580264199200904050","11040260598439082899724246594172595255","102902984756368774634858368204177306065","314347728697058253154040287090600650143","227873881412926585236247316298949108653","64532137672748543109270168754940114485","2478837315733749900781848260574210910"],"threshold":0.9},"id":"CVE-2026-8784-1419b285","signature_type":"Line"},{"id":"CVE-2026-8784-d1a78ac9","signature_type":"Function","signature_version":"v1","source":"https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f","target":{"function":"die","file":"cramfsck.c"},"deprecated":false,"digest":{"function_hash":"39294100263484989869914382135671155206","length":464}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}