MEDIUM
jtsylve
CVE published 2026-09-03
CVE-2026-85092
CVE-2026-85092 is a vulnerability in LiME through version 1.12.0 that allows unprivileged local users to overwrite arbitrary root-owned files due to a failure in validating the disk acquisition output path and not using O_NOFOLLOW when opening the operator-supplied path parameter. This vulnerability can be exploited by creating a symbolic link with the expected filename pointing to any root-owned file. De [truncated]