{"id":"openSUSE-SU-2026:20915-1","summary":"Security update for sshfs","details":"This update for sshfs fixes the following issues:\n\nChanges in sshfs:\n\n- Update to 3.7.6:\n  - Added new maintainer: abhinavagarwal07 Abhinav Agarwal\n  - CVE-2026-47187: Fixed critical vulnerability - Symlink\n    Escape: Rogue SFTP Server to Local File Read/Write), credit\n    to abhinavagarwal07 (bsc#1267017)\n  - New -o contain_symlinks and -o no_contain_symlinks to control\n    symlink containment behavior\n  - CVE-2026-48711: Fixed high severity vulnerability - Improper\n    Neutralization of Argument Delimiters in a Command ('Argument\n    Injection'), credit to abhinavagarwal07 (bsc#1267016)\n  - Fixed null-deref warning in tokenize_on_space, promote\n    strict-warnings to required\n  - Added a number of tests in CI, including rename, chmod,\n    fsync, statvfs values, error paths, option coverage\n  - Fixed malformed SFTP reply handling\n\n- Update to 3.7.5:\n  * Implement connect to vsock\n  * use latest major version for actions/checkout\n  * Fix memleak in cache after readlink\n  * Fill stat info when returning cached data for readdir\n  * ipv6 support for directport connection\n- reverts to original fork\n\n- Don't globstar files in shared directory _bindir.\n\n- build the man page\n","modified":"2026-06-09T09:00:07.240799459Z","published":"2026-06-05T21:40:06Z","related":["CVE-2026-47187","CVE-2026-48711"],"upstream":["CVE-2026-47187","CVE-2026-48711"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267016"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47187"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48711"}],"schema_version":"1.7.5"}