FUSE through version 3.2.4 is vulnerable to a bypass of the 'userallowother' restriction that allows, when SELinux is active, non-root users to mount FUSE file systems with the 'allowother' mount option. Local users can exploit this with the 'fusermount' command, bypassing the system configuration. This results in a mounted file system accessible by all other users including root.