CVE-2015-3202: Debian Linux

Low severity, CVSS 3.6. EPSS: 1% chance of exploitation in the next 30 days.

fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

Affected products

Published 2015-07-02. Last modified 2026-06-17.