Junglewise Threat Intelligence

CVE-2026-8274: npitre cramfs-tools path traversal in cramfsck

CVE-2026-8274 · Severity: medium · CVSS 5.3 · Published 2026-05-11

Executive brief

A vulnerability exists in cramfs-tools, a set of utilities used to create and check compressed file systems often found in embedded devices and firmware. When using the tool to extract a file system image, a specially crafted image can trick the software into writing files to locations on the computer outside of the intended folder. This could allow an attacker to overwrite sensitive system files or plant malicious software if they can convince a user or automated system to process a malicious image.

Technical details

A path traversal vulnerability exists in the 'do_directory' function within 'cramfsck.c' of cramfs-tools up to version 2.1. The 'cramfsck -x' utility reconstructs host filesystem paths by directly appending raw on-disk directory entry names to the extraction directory string without validating for path separators or traversal sequences. An attacker can provide a crafted cramfs image containing directory entries like '../pwn', which causes the tool to write files outside the intended extraction root. This vulnerability can be exploited in environments where cramfs images are automatically unpacked, such as firmware analysis pipelines. The issue is resolved in version 2.2 by rejecting directory entry names containing '/', '.', or '..'.

Affected products

  • npitre cramfs-tools up to 2.1

Timeline

  • 2026-04-22: disclosed: Issue reported on GitHub repository
  • 2026-05-11: advisory: CVE-2026-8274 published
  • 2026-05-11: patched: Version 2.2 released with fix

References

Related threats