MEDIUM
npitre cramfs-tools cramfsck.c change_file_status symlink
Published May 18, 2026
4.6
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue.
Affected products
-
- Version 2.0StatusaffectedConstraints-
- Version 2.1StatusaffectedConstraints-
- Version 2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Npitre | Cramfs-Tools | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30728 Advisory
- https://github.com/npitre/cramfs-tools/ product
- https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f patch
- https://github.com/npitre/cramfs-tools/issues/13 exploitissue-tracking
- https://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583 issue-tracking
- https://vuldb.com/submit/811897 third-party-advisory
- https://vuldb.com/vuln/364408 vdb-entrytechnical-description
- https://vuldb.com/vuln/364408/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30728 | Advisory | |
| https://github.com/npitre/cramfs-tools/ | product | |
| https://github.com/npitre/cramfs-tools/commit/b4a3a695c9873f824907bd15659f2a6ac7667b4f | patch | |
| https://github.com/npitre/cramfs-tools/issues/13 | exploitissue-tracking | |
| https://github.com/npitre/cramfs-tools/issues/13#issuecomment-4306102583 | issue-tracking | |
| https://vuldb.com/submit/811897 | third-party-advisory | |
| https://vuldb.com/vuln/364408 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/364408/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 18, 2026
Updated May 18, 2026
Reserved May 17, 2026
Link CVE-2026-8784
CISA Vulnrichment
Updated May 18, 2026
ENISA EUVD
EUVD-2026-30728 Assigner VulDB
Published May 18, 2026
Updated May 18, 2026
Exploited since n/a
Link EUVD-2026-30728