PatchSiren cyber security CVE debrief
CVE-2017-5940 Firejail Project CVE debrief
CVE-2017-5940 was publicly disclosed on 2017-02-09 and describes a Firejail sandbox escape issue caused by incomplete dotfile handling while trying to block access to user files with an euid of zero. The record states that local users could leverage a symlink and the --private option to bypass containment, and that the flaw existed because of an incomplete fix for CVE-2017-5180.
- Vendor
- Firejail Project
- Product
- Firejail
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Administrators and users running Firejail in environments that rely on local sandboxing, especially those using affected 0.9.38.x LTS or 0.9.40 through 0.9.44.6 releases and the --private option.
Technical summary
NVD classifies the issue as CVE-2017-5940 with CVSS 3.0 vector AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H and CWE-269. The vulnerability affects Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS. According to the record, Firejail did not comprehensively address dotfile cases in its attempt to prevent access to user files with euid 0, allowing a local attacker to conduct a sandbox-escape attack via a symlink and the --private option. The issue is described as an incomplete fix for CVE-2017-5180.
Defensive priority
High. The issue is local, but the impact is broad because a successful escape can compromise confidentiality, integrity, and availability within the sandbox boundary.
Recommended defensive actions
- Upgrade Firejail to a fixed release at or above 0.9.44.6, or 0.9.38.10 LTS for the LTS line.
- Audit systems to identify any deployments still using affected Firejail versions.
- Review uses of the --private option and verify that containment assumptions are still valid after upgrading.
- Track vendor release notes and linked patches to confirm the remediation path used in your environment.
- Prioritize patching on systems where untrusted local users can run code or where Firejail is used to isolate higher-risk applications.
Evidence notes
The official CVE record and NVD entry identify the affected version ranges, the CVSS score/vector, and the local attack model. The vendor release notes, mailing list reference, and linked commits are included in the source corpus as remediation evidence. The description explicitly ties this issue to incomplete handling of dotfiles and to the earlier CVE-2017-5180 fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5940 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5940
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5940 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5940
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://firejail.wordpress.com/download-2/release-notes/
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/netblue30/firejail/commit/38d418505e9ee2d326557e5639e8da49c298858f
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/netblue30/firejail/commit/903fd8a0789ca3cc3c21d84cd0282481515592ef
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/netblue30/firejail/commit/b8a4ff9775318ca5e679183884a6a63f3da8f863
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-03
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.