Junglewise Threat Intelligence

CVE-2026-82457: ncopa su-exec integer truncation in UID/GID parsing

CVE-2026-82457 · Severity: high · CVSS 7.8 · Published 2026-08-29

Executive brief

su-exec is a lightweight privilege-dropping utility commonly used in container entrypoints to run services as non-root users. A vulnerability in numeric UID/GID parsing allows attackers who control runtime environment variables (such as PUID/PGID) to supply out-of-range values that wrap to zero, causing the target process to execute as root instead of the intended unprivileged user. This bypasses a critical security boundary in containerized environments.

Technical details

The vulnerability is an integer wraparound flaw in numeric UID/GID parsing. su-exec uses strtol() to parse numeric user and group identifiers but fails to validate the parsed values before assigning them to uid_t/gid_t types. On systems where uid_t/gid_t are 32-bit, values like 4294967296 wrap to 0 (root's UID). The vulnerable code path occurs directly at the privilege boundary—after strtol() parsing but before setgid()/setuid()/execvp() calls—making exploitation straightforward in container entrypoints that pass attacker-controlled environment variables (e.g., PUID/PGID). The root cause includes missing range validation, no checks for ERANGE, and failure to reject negative signs. An attacker controlling runtime identity values in a containerized application can achieve arbitrary code execution as UID 0 without escaping the container.

Affected products

  • ncopa su-exec through 0.3

Timeline

  • 2026-08-29: disclosed

References