https://reddit.com/r/netsec/comments/1uknvr4/privilege_escalation_to_root_in_lima_qemu_guests/: Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
Published Jul 1, 2026
·Updated
Affected Software
1 affected component
QEMU=
Frequently Asked Questions
1
What is the severity of CVE-2026-53657?
CVE-2026-53657 is rated as a high-severity vulnerability due to its potential for privilege escalation to root in Lima QEMU guests.
2
How do I fix CVE-2026-53657?
To mitigate CVE-2026-53657, ensure that the agent socket is not world-writable and restrict permissions appropriately on the QEMU guest.
3
What systems are affected by CVE-2026-53657?
CVE-2026-53657 affects QEMU guests running within the Lima hypervisor environment.
4
What is the attack vector for CVE-2026-53657?
The attack vector for CVE-2026-53657 is through a malicious actor exploiting a world-writable agent socket to escalate privileges to root.
5
Is there a workaround for CVE-2026-53657?
A potential workaround for CVE-2026-53657 includes removing or securing world-writable permissions on agent sockets used by QEMU guests.