CVE-2015-3202

FUSE <2.9.3-15 - Local Privilege Escalation

Title source: llm

Description

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tavis Ormandy · textlocallinux
https://www.exploit-db.com/exploits/37089

References (22)

... and 2 more

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-264
Status draft

Affected Products (2)

debian/debian_linux
fuse_project/fuse < 2.9.2

Timeline

Published Jul 02, 2015
Tracked Since Feb 18, 2026