Linux Kernel

•

severity

7.8

published

An oversized directory entry returned by a malicious FUSE server can overflow a Linux kernel page-cache page by 24 attacker-controlled bytes. Bynario demonstrated a working local privilege escalation on Ubuntu 26.04 by steering the overflow into the cached code of the SUID /usr/bin/su binary and executing the corrupted binary to obtain a root shell.

fuse_add_dirent_to_cache() checked whether a serialized directory entry fit in the remaining space of the current page, but did not reject an entry that was itself larger than PAGE_SIZE. A malicious FUSE server could set namelen to 4,095 and cause memcpy() to overwrite the following kernel page. The fix rejects directory entries that cannot fit within a single page before adding them to the readdir cache. Bynario classifies the issue as CWE-787; NVD currently provides no specific CWE.

The demonstrated exploit used unprivileged FUSE mounting to place a controlled page beside a cached page from /usr/bin/su. It overwrote the first 24 bytes of the binary's .init section with code that set the effective UID and GID to zero. Executing the corrupted cached binary then produced a root shell without modifying the file on disk.


References

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SGtCaFr9tT  lHo1oSk5i7nWgH  aEtX  yUoRu8rS  sLoWfHtOwXaEr7e#  cIrAiNtNiFcVaMl7l8yX.P

request briefing

request briefing

SPtTa$rYtG  lBoDoFkKi4n1gY  a7t%  y0o4uGr#  sJo3fAtMw0a0rJeZ  c1r8i6t7iQcSa@lPl2y5.G

request briefing

request briefing

S3tUaCr9t3  lOoDoXkTiAnPgH  aKtU  y7oPu&rJ  sSoCfFtCwLaTrBeW  cBrLiAt5iYcDaYl3l3yD.0

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026