https://reddit.com/r/Infosec/comments/1uklf0i/privilege_escalation_to_root_in_lima_qemu_guests/: Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
Published Jul 1, 2026
·Updated
Affected Software
1 affected component
Lima Lima<2.1.3
Frequently Asked Questions
1
What is the severity of CVE-2026-53657?
CVE-2026-53657 has a severity score of High, with a CVSS rating of 8.2.
2
How does CVE-2026-53657 affect Lima QEMU guests?
CVE-2026-53657 allows an unprivileged user inside a Lima QEMU guest to execute commands as root through a world-writable agent socket.
3
What versions of Lima are affected by CVE-2026-53657?
CVE-2026-53657 affects versions of Lima prior to v2.1.3.
4
How do I fix CVE-2026-53657?
To fix CVE-2026-53657, upgrade to Lima version 2.1.3 or later.
5
What is the scope of CVE-2026-53657?
The scope of CVE-2026-53657 is classified as Changed, indicating that the vulnerability allows crossing from an unprivileged account to root within the VM.