Updated fuse-overlayfs package fixes security vulnerabilities
Publication date: 29 Sep 2026Modification date: 29 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-52791 , CVE-2026-77478
Description
fuse-overlayfs release-1.x preserves SUID/SGID bits after
truncate/open(O_TRUNC). (CVE-2026-52791)
Operations on hardlinked lower-layer files resolving to the wrong layer.
(CVE-2026-77478)
References
- https://bugs.mageia.org/show_bug.cgi?id=36164
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OHDCW47LEOQXLVH2XJNC3A7VFVELJQ6U/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YO4BSFYJPI6ZGUIXZ3AHYYYFEYEM4MFO/
- https://github.com/containers/fuse-overlayfs/releases/tag/v1.17
- https://github.com/containers/fuse-overlayfs/releases/tag/v1.18
- https://www.cve.org/CVERecord?id=CVE-2026-52791
- https://www.cve.org/CVERecord?id=CVE-2026-77478
SRPMS
10/core
- fuse-overlayfs-1.18-1.mga10