https://reddit.com/r/cybersecurity/comments/1ukmkio/privilege_escalation_to_root_in_lima_qemu_guests/: Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
Published Jul 1, 2026
·Updated
Affected Software
1 affected component
Lima Lima (QEMU guest agent socket)<2.1.3
Frequently Asked Questions
1
What is the severity of CVE-2026-53657?
CVE-2026-53657 has a severity rating of High with a CVSS score of 8.2.
2
How do I fix CVE-2026-53657?
To remediate CVE-2026-53657, upgrade to Lima version 2.1.3 or later.
3
Who is affected by CVE-2026-53657?
CVE-2026-53657 affects users with unprivileged accounts in Lima QEMU guests.
4
What types of systems does CVE-2026-53657 impact?
CVE-2026-53657 impacts systems running Lima with QEMU guest agent socket.
5
What are the potential risks of CVE-2026-53657?
The potential risk of CVE-2026-53657 is that an unprivileged user can execute commands as root within the VM.