CVE-2015-3202: Debian Linux
Low severity, CVSS 3.6. EPSS: 1% chance of exploitation in the next 30 days.
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
Affected products
- Debian Debian Linux: version 8.0 only
- Fuse Project Fuse: up to and including 2.9.2
Published 2015-07-02. Last modified 2026-06-17.