Description
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
Published: 2026-09-30
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file overwrite leading to potential privilege escalation or system compromise
Action: Apply Patch
AI Analysis

Impact

PFU Limited’s Image Scanner Driver for Linux contains a link following vulnerability that permits local logged‑in users to overwrite arbitrary files. This flaw can be triggered by a special method supplied with the driver and is not limited to configuration files; any file on the system can be replaced, enabling attackers to modify binaries or other critical resources.

Affected Systems

The vulnerability affects the PFU Limited Image Scanner Driver for Linux for both the SP Series and the fi Series. No specific version information is listed, meaning all installed instances of the driver are potentially impacted.

Risk and Exploitability

The CVSS score of 5.2 places the flaw in a moderate risk range. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The exploit requires local access to a Linux system where the driver is installed; an attacker must be able to authenticate locally to leverage the vulnerable method. Once the method is executed, any file that the user has permission to overwrite can be altered, which may enable privilege escalation or lead to denial of service if critical system components are tampered with.

Generated by OpenCVE AI on September 30, 2026 at 08:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch or updated driver released by PFU Limited that addresses the CWE‑59 link following flaw.
  • Restrict the driver’s execution to users with the least privileges necessary; harden file system permissions so that even authenticated local users cannot unintentionally follow hidden links to system files, mitigating the CWE‑59 vulnerability.
  • Enable file‑integrity monitoring on directories the driver accesses to detect if any file has been unexpectedly overwritten as a result of the CWE‑59 issue.
  • As a temporary measure where no patch exists, sandbox the driver in a container or chroot to prevent it from reaching critical parts of the host file system.

Generated by OpenCVE AI on September 30, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Link Following Vulnerability Allowing Arbitrary File Overwrite in PFU Image Scanner Driver for Linux

Wed, 30 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T01:51:54.487Z

Reserved: 2026-09-04T00:52:01.540Z

Link: CVE-2026-81310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T02:16:57.747

Modified: 2026-09-30T16:47:57.730

Link: CVE-2026-81310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:30:08Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')