The Fuse Project maintains a narrowly scoped filesystem abstraction framework, with its vulnerability footprint centered on the single Fuse product and reflecting access-control challenges inherent to a user-space filesystem interface. The recurring weakness classes—improper authorization and improper privilege management—align with the boundary between kernel and application privilege domains that the framework traverses. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fuse Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10906HIGH In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system | Jul 24, 2018 | 7.8 | 36 | NO | YES |
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via | Jul 2, 2015 | 3.6 | 22 | NO | YES |
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local use | Jun 3, 2005 | 2.1 | 17 | NO | YES |
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access re | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified ve | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack. | Sep 2, 2011 | 3.3 | 16 | NO | NO |
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint. | Mar 2, 2010 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fuse Project.
Media articles that mention a CVE ID that affects a product developed by Fuse Project — matched by CVE ID, not by vendor name.