{"id":"MGASA-2026-0462","summary":"Updated fuse-overlayfs package fixes security vulnerabilities","details":"fuse-overlayfs release-1.x preserves SUID/SGID bits after\ntruncate/open(O_TRUNC). (CVE-2026-52791)\nOperations on hardlinked lower-layer files resolving to the wrong layer.\n(CVE-2026-77478)\n","modified":"2026-09-29T19:15:04.664714441Z","published":"2026-09-29T19:12:34Z","upstream":["CVE-2026-52791","CVE-2026-77478"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0462.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36164"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OHDCW47LEOQXLVH2XJNC3A7VFVELJQ6U/"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YO4BSFYJPI6ZGUIXZ3AHYYYFEYEM4MFO/"},{"type":"WEB","url":"https://github.com/containers/fuse-overlayfs/releases/tag/v1.17"},{"type":"WEB","url":"https://github.com/containers/fuse-overlayfs/releases/tag/v1.18"}],"affected":[{"package":{"name":"fuse-overlayfs","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/fuse-overlayfs?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0462.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}