{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/su-exec--0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:su-exec_project:su-exec:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-82457"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["su-exec (\u003c= 0.3)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability","linux"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe su-exec utility, a tool commonly used to step down from root privileges to a specific unprivileged user in containerized environments, contains a critical integer overflow and truncation vulnerability (CVE-2026-82457). The software uses the strtol function to parse user and group identifiers from command-line arguments but fails to validate the resulting numeric range before casting these values to uid_t and gid_t types.\u003c/p\u003e\n\u003cp\u003eIf an attacker provides an extremely large numeric identifier as input, the underlying system cast causes the value to truncate, wrapping around to zero, which corresponds to the root user identifier. Consequently, su-exec may fail to transition to the intended unprivileged user and instead execute the target command with full root privileges. This vulnerability impacts all versions of su-exec up to and including 0.3, posing a significant risk in environments where this utility is used as a security boundary for container entrypoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-82457 results in an attacker gaining unauthorized root-level access on the host or container, bypassing intended access controls. This vulnerability primarily affects Linux-based container environments that utilize su-exec to manage process user privileges. If exploited, an attacker can maintain persistent root access, modify system files, or move laterally within the containerized environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of su-exec 0.3 or older within the environment, particularly within container images and orchestration configurations.\u003c/li\u003e\n\u003cli\u003ePatch or upgrade the su-exec dependency to a version that addresses CVE-2026-82457 as soon as a fix is available from the maintainer.\u003c/li\u003e\n\u003cli\u003eAudit container entrypoint scripts that invoke su-exec to ensure they do not accept untrusted user-supplied input for UID/GID arguments.\u003c/li\u003e\n\u003cli\u003eEnforce the use of non-root users at the container orchestration level (e.g., Kubernetes SecurityContext) to minimize the impact of successful privilege escalation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T15:40:12Z","date_published":"2026-08-29T15:40:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-suexec-truncation/","summary":"The su-exec utility up to version 0.3 suffers from integer truncation during user identifier parsing, allowing attackers to escalate privileges to root.","title":"CVE-2026-82457 Privilege Escalation in su-exec","url":"https://feed.craftedsignal.io/briefs/2026-08-suexec-truncation/"}],"language":"en","title":"CraftedSignal Threat Feed - Su-Exec (\u003c= 0.3)","version":"https://jsonfeed.org/version/1.1"}