PatchSiren

jtsylve CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM jtsylve CVE published 2026-09-03

CVE-2026-85092

CVE-2026-85092 is a vulnerability in LiME through version 1.12.0 that allows unprivileged local users to overwrite arbitrary root-owned files due to a failure in validating the disk acquisition output path and not using O_NOFOLLOW when opening the operator-supplied path parameter. This vulnerability can be exploited by creating a symbolic link with the expected filename pointing to any root-owned file. De [truncated]