HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-82457 — su-exec through 0.3 fails to validate numeric user and group identifiers parsed ...

·Source: NIST NVD

Updated:

Executive Summary

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.

Analysis

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts. CVSS Score: 7.8. Published: 2026-08-29T14:16:38.910.

Indicators of Compromise (1)

CVE (1)
CVE-2026-82457
Source Attribution

Originally published by NIST NVD on Aug 29, 2026. Verified by: NIST.

Related Threats