LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can create a symbolic link with the expected filename pointing to any root-owned file, and when the acquisition runs in kernel context, LiME follows the link and truncates the target file with the memory acquisition stream.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jtsylve
Jtsylve lime |
|
| Vendors & Products |
Jtsylve
Jtsylve lime |
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can create a symbolic link with the expected filename pointing to any root-owned file, and when the acquisition runs in kernel context, LiME follows the link and truncates the target file with the memory acquisition stream. | |
| Title | LiME through 1.12.0 Arbitrary File Overwrite via Symlink Following | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T01:04:45.189Z
Updated: 2026-09-03T14:30:54.637Z
Reserved: 2026-09-02T23:53:09.796Z
Link: CVE-2026-85092
Updated: 2026-09-03T13:13:56.091Z
Status : Received
Published: 2026-09-03T13:06:20.720
Modified: 2026-09-03T15:17:37.000
Link: CVE-2026-85092
No data.