https://reddit.com/r/netsec/comments/1ukle4i/privilege_escalation_to_root_in_lima_qemu_guests/: Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
Published Jul 1, 2026
·Updated
Affected Software
1 affected component
Lima Lima QEMU guest agent<2.1.3
Frequently Asked Questions
1
What is the severity of CVE-2026-53657?
CVE-2026-53657 has been rated as High severity with a CVSS score of 8.2.
2
How do I fix CVE-2026-53657?
To fix CVE-2026-53657, upgrade to Lima version 2.1.3 or later.
3
What causes CVE-2026-53657?
CVE-2026-53657 is caused by an unprivileged user inside a Lima QEMU guest being able to access a world-writable agent socket and execute commands as root.
4
Who is affected by CVE-2026-53657?
CVE-2026-53657 affects users operating within a Lima QEMU guest environment.
5
What is the impact of CVE-2026-53657?
The impact of CVE-2026-53657 is that it allows an unprivileged user to escalate privileges to root within the guest VM.