CVE-2026-49413
Flaw in Linuxulator execution of setugid binaries
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.1EPSS 0.1%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
10 Jun 2026Public PoC
27 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and set-group-ID executables.
An unprivileged local user can inject a shared library via LD_PRELOAD into a set-user-ID or set-group-ID Linux binary, gaining the privileges of that binary.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected products
FreeBSD · FreeBSDpublic PoCs found — 1
githubgithub.com/ii4gsp/CVE-2026-49413★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →