Opened 4 months ago

Closed 4 months ago

#23383 closed enhancement (fixed)

sshfs-3.7.6

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → high
Status: assigned → new
Release 3.7.6 (2026-05-30)
--------------------------

* Added new maintainer: abhinavagarwal07 Abhinav Agarwal
* Fixed critical vulnerability CVE-2026-47187 - Symlink Escape: Rogue SFTP Server to Local File Read/Write), credit to abhinavagarwal07
* New -o contain_symlinks and -o no_contain_symlinks to control symlink containment behavior
* Fixed high severity vulnerability CVE-2026-48711 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), credit to abhinavagarwal07
* Fixed null-deref warning in tokenize_on_space, promote strict-warnings to required
* Added a number of tests in CI, including rename, chmod, fsync, statvfs values, error paths, option coverage
* Fixed malformed SFTP reply handling
* Hardened Github Actions workflow with SHA pins, permissions, timeouts, and dependabot

Fixed at 9dc987c3c2. Leaving open for SA.

comment:3 by Douglas R. Reno, 4 months ago

Additional details on the security vulnerabilities:

Two vulnerabilities in sshfs (FUSE filesystem over SFTP) have been
assigned CVEs and fixed in sshfs 3.7.6.

Affected versions: sshfs <= 3.7.5
Fixed in: sshfs 3.7.6
https://github.com/libfuse/sshfs/releases/tag/sshfs-3.7.6


CVE-2026-47187: Symlink escape - rogue SFTP server -> local file read/write
Severity: Critical (CVSS 9.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
CWE: CWE-59 (Improper Link Resolution Before File Access)

A rogue SFTP server can return symlink targets (absolute paths or
relative "../../../" escapes) that sshfs passes to the kernel
unchanged. The kernel resolves them on the client's local filesystem,
so an ordinary "cp" through the mountpoint can read local files back
to the server or write server-controlled bytes to local files.
transform_symlinks does not cover relative targets.

Fixed by a new contain_symlinks option (default on) that rejects
absolute targets and any target containing "..", returning EPERM.

Advisory:
https://github.com/libfuse/sshfs/security/advisories/GHSA-pjv6-2c3f-r357
Credit: Abhinav Agarwal (reporter)


CVE-2026-48711: ssh argument injection via bracketed mount source
Severity: High (CVSS 7.0, CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CWE: CWE-88 (Argument Injection)
Confirmed affected: sshfs 1.4 through 3.7.5

A mount source such as "[-oProxyCommand=CMD]:/path" is accepted as a
positional source; find_base_path() strips the brackets as an IPv6
literal, leaving "-oProxyCommand=CMD" as the hostname, which sshfs
passes to ssh as an option. When the caller sets a path-valued
sftp_server, ssh gets a destination argument and runs the injected
ProxyCommand before connecting, giving arbitrary local command
execution as the user running sshfs, with no SSH authentication.
Requires a caller that passes an attacker-controlled mount source and
uses a path-valued sftp_server.

Fixed by rejecting hostnames that begin with "-" after bracket
normalization, and adding an ssh end-of-options marker ("--") before
the hostname.

Advisory:
https://github.com/libfuse/sshfs/security/advisories/GHSA-mm85-q63v-4476
Credit: Abhinav Agarwal (reporter)


Both issues were reported privately to the sshfs maintainer through
GitHub's private vulnerability reporting and fixed in a coordinated
release.

Timeline (UTC):
2026-05-16 CVE-2026-47187 (symlink escape) reported
2026-05-18 CVE-2026-48711 (argument injection) reported
2026-05-29 GHSA advisories published
2026-05-29 sshfs 3.7.6 released with fixes for both

-- Abhinav Agarwal

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-117 issued

Note: See TracTickets for help on using tickets.