Fuse is a narrowly scoped filesystem project where the observed vulnerability surface centers on its core product and clusters around improper link resolution and file-access ordering issues, reflecting the privilege boundaries and symlink-handling complexities inherent to a user-space filesystem interface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fuse over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10906HIGH In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system | Jul 24, 2018 | 7.8 | 36 | NO | YES |
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via | Jul 2, 2015 | 3.6 | 22 | NO | YES |
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local use | Jun 3, 2005 | 2.1 | 17 | NO | YES |
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access re | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified ve | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack. | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint. | Mar 2, 2010 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fuse.
Media articles that mention a CVE ID that affects a product developed by Fuse — matched by CVE ID, not by vendor name.