{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lima--2.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-53657"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Lima (\u003c= 2.1.2)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","virtualization","cve-2026-53657"],"_cs_type":"advisory","_cs_vendors":["Lima"],"content_html":"\u003cp\u003eLima, a project providing Linux virtual machines on macOS, contains a vulnerability (CVE-2026-53657) affecting instances using the QEMU driver. An arbitrary user within the guest VM can access the guest agent Unix socket located at /run/lima-guestagent.sock. Because this socket provides tunneling services for arbitrary addresses, including those used by privileged system daemons like D-Bus, an unprivileged user can craft requests to execute arbitrary commands with root privileges within the guest instance. This issue is specific to the QEMU driver; the 'vz' driver is unaffected as it utilizes vsocks. The vulnerability is patched in Lima version 2.1.3.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for local privilege escalation (LPE) within the context of a Lima virtual machine. Successful exploitation grants an unprivileged guest user root-level command execution. The scope is limited to the VM instance itself and does not directly result in root access on the macOS host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Lima installation to version 2.1.3 or higher to address CVE-2026-53657.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, switch to the 'vz' driver for VM instances using 'limactl create --vm-type=vz' or disable the guest agent using the '--plain' flag during VM creation.\u003c/li\u003e\n\u003cli\u003eAudit existing VM configurations to identify instances currently using the QEMU driver.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T20:06:58Z","date_published":"2026-08-14T20:06:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-lima-guest-agent-privesc/","summary":"An arbitrary user within a QEMU-based Lima VM can exploit improper access controls on the guest agent Unix socket (/run/lima-guestagent.sock) to execute arbitrary commands with root privileges within the guest VM.","title":"Local Privilege Escalation in Lima via Guest Agent Socket","url":"https://feed.craftedsignal.io/briefs/2026-08-lima-guest-agent-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Lima (\u003c= 2.1.2)","version":"https://jsonfeed.org/version/1.1"}