{
  "claim_outcome": "confirmed",
  "claim_block_reason": null,
  "repro_result": "confirmed",
  "validated_surface": "local_only",
  "evidence_scope": "production_path",
  "claimed_impact_class": "privilege_escalation",
  "observed_impact_class": "privilege_escalation",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "malicious FUSE server READDIR reply with namelen=4095 and payload root::0:0:x:.:\\n#######",
  "trigger_path": "uid 1000 FUSE daemon -> getdents64 -> fuse_readdir_uncached -> fuse_emit -> fuse_add_dirent_to_cache -> memcpy oversized dirent into readdir cache page -> /etc/passwd page-cache first line changed",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "blocking_mitigation": null,
  "inferred": false
}