Find a vulnerability
Search criteria
Related vulnerabilities
BELL-CVE-2026-53612 (CVE-2026-53612)
Vulnerability from osv_bellsoft – Published: 2026-06-19 06:12 – Updated: 2026-08-05 06:01 – Source website| URL | Type | |
|---|---|---|
{
"affected": [
{
"package": {
"ecosystem": "Alpaquita:25",
"name": "util-linux",
"purl": "pkg:apk/alpaquita/util-linux?arch=source\u0026distro=25"
},
"ranges": [
{
"events": [
{
"introduced": "2.41-r6"
},
{
"fixed": "2.41.5-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Alpaquita:stream",
"name": "util-linux",
"purl": "pkg:apk/alpaquita/util-linux?arch=source\u0026distro=stream"
},
"ranges": [
{
"events": [
{
"introduced": "2.39-r14"
},
{
"fixed": "2.42.2-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "BellSoft Hardened Containers:25",
"name": "util-linux",
"purl": "pkg:apk/bellsoft-hardened-containers/util-linux?arch=source\u0026distro=25"
},
"ranges": [
{
"events": [
{
"introduced": "2.41-r6"
},
{
"fixed": "2.41.5-r0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "BellSoft Hardened Containers:stream",
"name": "util-linux",
"purl": "pkg:apk/bellsoft-hardened-containers/util-linux?arch=source\u0026distro=stream"
},
"ranges": [
{
"events": [
{
"introduced": "2.39-r14"
},
{
"fixed": "2.42.2-r0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"id": "BELL-CVE-2026-53612",
"modified": "2026-08-05T06:01:24.3079Z",
"published": "2026-06-19T06:12:42.866249Z",
"references": [
{
"type": "ADVISORY",
"url": "https://docs.bell-sw.com/security/cves/CVE-2026-53612"
}
],
"schema_version": "1.7.4",
"upstream": [
"CVE-2026-53612"
]
}
CERTFR-2026-AVI-1068
Vulnerability from certfr_avis - Published: 2026-08-21 - Updated: 2026-08-21
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Debian trixie versions ant\u00e9rieures \u00e0 2.41.5-0+deb13u1",
"product": {
"name": "Debian",
"vendor": {
"name": "Debian",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-53613",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
},
{
"name": "CVE-2026-53614",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53614"
},
{
"name": "CVE-2026-27456",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
},
{
"name": "CVE-2026-13595",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
},
{
"name": "CVE-2026-53612",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53612"
}
],
"initial_release_date": "2026-08-21T00:00:00",
"last_revision_date": "2026-08-21T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1068",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-08-21T00:00:00.000000"
}
],
"risks": [
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de Debian. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de Debian",
"vendor_advisories": [
{
"published_at": "2026-08-14",
"title": "Bulletin de s\u00e9curit\u00e9 Debian msg00353",
"url": "https://lists.debian.org/debian-security-announce/2026/msg00353.html"
}
]
}
OESA-2026-3980 (CVE-2026-53612)
Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source websiteThe util-linux package contains a random collection of files that implements some low-level basic linux utilities.
Security Fix(es):
CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)
When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)
A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)
{
"affected": [
{
"ecosystem_specific": {
"aarch64": [
"libblkid-2.39.1-44.oe2403sp1.aarch64.rpm",
"libfdisk-2.39.1-44.oe2403sp1.aarch64.rpm",
"libmount-2.39.1-44.oe2403sp1.aarch64.rpm",
"libsmartcols-2.39.1-44.oe2403sp1.aarch64.rpm",
"libuuid-2.39.1-44.oe2403sp1.aarch64.rpm",
"python3-libmount-2.39.1-44.oe2403sp1.aarch64.rpm",
"util-linux-2.39.1-44.oe2403sp1.aarch64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp1.aarch64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp1.aarch64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp1.aarch64.rpm",
"util-linux-user-2.39.1-44.oe2403sp1.aarch64.rpm",
"uuidd-2.39.1-44.oe2403sp1.aarch64.rpm"
],
"noarch": [
"util-linux-help-2.39.1-44.oe2403sp1.noarch.rpm"
],
"src": [
"util-linux-2.39.1-44.oe2403sp1.src.rpm"
],
"x86_64": [
"libblkid-2.39.1-44.oe2403sp1.x86_64.rpm",
"libfdisk-2.39.1-44.oe2403sp1.x86_64.rpm",
"libmount-2.39.1-44.oe2403sp1.x86_64.rpm",
"libsmartcols-2.39.1-44.oe2403sp1.x86_64.rpm",
"libuuid-2.39.1-44.oe2403sp1.x86_64.rpm",
"python3-libmount-2.39.1-44.oe2403sp1.x86_64.rpm",
"util-linux-2.39.1-44.oe2403sp1.x86_64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp1.x86_64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp1.x86_64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp1.x86_64.rpm",
"util-linux-user-2.39.1-44.oe2403sp1.x86_64.rpm",
"uuidd-2.39.1-44.oe2403sp1.x86_64.rpm"
]
},
"package": {
"ecosystem": "openEuler:24.03-LTS-SP1",
"name": "util-linux",
"purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP1"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.39.1-44.oe2403sp1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"severity": "High"
},
"details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
"id": "OESA-2026-3980",
"modified": "2026-09-20T13:23:47Z",
"published": "2026-09-20T13:23:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3980"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
}
],
"schema_version": "1.7.2",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "util-linux security update",
"upstream": [
"CVE-2026-53612",
"CVE-2026-53613",
"CVE-2026-53614",
"CVE-2026-78410"
]
}
OESA-2026-3981 (CVE-2026-53612)
Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source websiteThe util-linux package contains a random collection of files that implements some low-level basic linux utilities.
Security Fix(es):
CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)
When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)
A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)
util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.(CVE-2026-76642)
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)
{
"affected": [
{
"ecosystem_specific": {
"aarch64": [
"libblkid-2.39.1-44.oe2403sp3.aarch64.rpm",
"libfdisk-2.39.1-44.oe2403sp3.aarch64.rpm",
"libmount-2.39.1-44.oe2403sp3.aarch64.rpm",
"libsmartcols-2.39.1-44.oe2403sp3.aarch64.rpm",
"libuuid-2.39.1-44.oe2403sp3.aarch64.rpm",
"python3-libmount-2.39.1-44.oe2403sp3.aarch64.rpm",
"util-linux-2.39.1-44.oe2403sp3.aarch64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp3.aarch64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp3.aarch64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp3.aarch64.rpm",
"util-linux-user-2.39.1-44.oe2403sp3.aarch64.rpm",
"uuidd-2.39.1-44.oe2403sp3.aarch64.rpm"
],
"noarch": [
"util-linux-help-2.39.1-44.oe2403sp3.noarch.rpm"
],
"src": [
"util-linux-2.39.1-44.oe2403sp3.src.rpm"
],
"x86_64": [
"libblkid-2.39.1-44.oe2403sp3.x86_64.rpm",
"libfdisk-2.39.1-44.oe2403sp3.x86_64.rpm",
"libmount-2.39.1-44.oe2403sp3.x86_64.rpm",
"libsmartcols-2.39.1-44.oe2403sp3.x86_64.rpm",
"libuuid-2.39.1-44.oe2403sp3.x86_64.rpm",
"python3-libmount-2.39.1-44.oe2403sp3.x86_64.rpm",
"util-linux-2.39.1-44.oe2403sp3.x86_64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp3.x86_64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp3.x86_64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp3.x86_64.rpm",
"util-linux-user-2.39.1-44.oe2403sp3.x86_64.rpm",
"uuidd-2.39.1-44.oe2403sp3.x86_64.rpm"
]
},
"package": {
"ecosystem": "openEuler:24.03-LTS-SP3",
"name": "util-linux",
"purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP3"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.39.1-44.oe2403sp3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"severity": "High"
},
"details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.(CVE-2026-76642)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
"id": "OESA-2026-3981",
"modified": "2026-09-20T13:23:47Z",
"published": "2026-09-20T13:23:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3981"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76642"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
}
],
"schema_version": "1.7.2",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "util-linux security update",
"upstream": [
"CVE-2026-53612",
"CVE-2026-53613",
"CVE-2026-53614",
"CVE-2026-76642",
"CVE-2026-78410"
]
}
OESA-2026-4073 (CVE-2026-53612)
Vulnerability from osv_openeuler – Published: 2026-09-25 01:28 – Updated: 2026-09-25 01:28 – Source websiteThe util-linux package contains a random collection of files that implements some low-level basic linux utilities.
Security Fix(es):
CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)
When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)
A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)
{
"affected": [
{
"ecosystem_specific": {
"aarch64": [
"libblkid-2.39.1-44.oe2403sp4.aarch64.rpm",
"libfdisk-2.39.1-44.oe2403sp4.aarch64.rpm",
"libmount-2.39.1-44.oe2403sp4.aarch64.rpm",
"libsmartcols-2.39.1-44.oe2403sp4.aarch64.rpm",
"libuuid-2.39.1-44.oe2403sp4.aarch64.rpm",
"python3-libmount-2.39.1-44.oe2403sp4.aarch64.rpm",
"util-linux-2.39.1-44.oe2403sp4.aarch64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp4.aarch64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp4.aarch64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp4.aarch64.rpm",
"util-linux-user-2.39.1-44.oe2403sp4.aarch64.rpm",
"uuidd-2.39.1-44.oe2403sp4.aarch64.rpm"
],
"noarch": [
"util-linux-help-2.39.1-44.oe2403sp4.noarch.rpm"
],
"src": [
"util-linux-2.39.1-44.oe2403sp4.src.rpm"
],
"x86_64": [
"libblkid-2.39.1-44.oe2403sp4.x86_64.rpm",
"libfdisk-2.39.1-44.oe2403sp4.x86_64.rpm",
"libmount-2.39.1-44.oe2403sp4.x86_64.rpm",
"libsmartcols-2.39.1-44.oe2403sp4.x86_64.rpm",
"libuuid-2.39.1-44.oe2403sp4.x86_64.rpm",
"python3-libmount-2.39.1-44.oe2403sp4.x86_64.rpm",
"util-linux-2.39.1-44.oe2403sp4.x86_64.rpm",
"util-linux-debuginfo-2.39.1-44.oe2403sp4.x86_64.rpm",
"util-linux-debugsource-2.39.1-44.oe2403sp4.x86_64.rpm",
"util-linux-devel-2.39.1-44.oe2403sp4.x86_64.rpm",
"util-linux-user-2.39.1-44.oe2403sp4.x86_64.rpm",
"uuidd-2.39.1-44.oe2403sp4.x86_64.rpm"
]
},
"package": {
"ecosystem": "openEuler:24.03-LTS-SP4",
"name": "util-linux",
"purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP4"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.39.1-44.oe2403sp4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"severity": "High"
},
"details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
"id": "OESA-2026-4073",
"modified": "2026-09-25T01:28:04Z",
"published": "2026-09-25T01:28:04Z",
"references": [
{
"type": "ADVISORY",
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4073"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
}
],
"schema_version": "1.7.2",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "util-linux security update",
"upstream": [
"CVE-2026-53612",
"CVE-2026-53613",
"CVE-2026-53614",
"CVE-2026-78410"
]
}
OPENSUSE-SU-2026:11408-1
Vulnerability from csaf_opensuse - Published: 2026-07-29 00:00 - Updated: 2026-09-26 08:34OPENSUSE-SU-2026:21905-1
Vulnerability from csaf_opensuse - Published: 2026-09-22 07:23 - Updated: 2026-09-26 08:35SUSE-SU-2026:23250-1
Vulnerability from csaf_suse - Published: 2026-08-21 14:17 - Updated: 2026-09-26 08:30SUSE-SU-2026:23255-1
Vulnerability from csaf_suse - Published: 2026-08-24 15:02 - Updated: 2026-09-26 08:30SUSE-SU-2026:23861-1
Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-27 11:06SUSE-SU-2026:23870-1
Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-27 11:06SUSE-SU-2026:23884-1
Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-30 11:15SUSE-SU-2026:3685-1
Vulnerability from csaf_suse - Published: 2026-08-21 18:24 - Updated: 2026-09-26 08:32UBUNTU-CVE-2026-53612 (CVE-2026-53612)
Vulnerability from osv_ubuntu – Published: 2026-06-18 00:00 – Updated: 2026-08-31 19:57 – Source website[Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown]
{
"affected": [
{
"ecosystem_specific": {
"availability": "No subscription required",
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.39.3-9ubuntu6.6"
},
{
"binary_name": "eject",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "fdisk",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libblkid1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libmount1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libuuid1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "mount",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "rfkill",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.39.3-9ubuntu6.6"
}
]
},
"package": {
"ecosystem": "Ubuntu:24.04:LTS",
"name": "util-linux",
"purl": "pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=source\u0026distro=noble"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.39.3-9ubuntu6.6"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.39.1-4ubuntu2",
"2.39.2-6ubuntu1",
"2.39.3-6ubuntu2",
"2.39.3-9ubuntu2",
"2.39.3-9ubuntu4",
"2.39.3-9ubuntu6",
"2.39.3-9ubuntu6.1",
"2.39.3-9ubuntu6.2",
"2.39.3-9ubuntu6.3",
"2.39.3-9ubuntu6.4",
"2.39.3-9ubuntu6.5"
]
},
{
"ecosystem_specific": {
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.41-4ubuntu4.2"
},
{
"binary_name": "eject",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "fdisk",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "lastlog2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libblkid1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "liblastlog2-2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libmount1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libpam-lastlog2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libuuid1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "login",
"binary_version": "1:4.16.0-2+really2.41-4ubuntu4.2"
},
{
"binary_name": "mount",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "rfkill",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.41-4ubuntu4.2"
}
]
},
"package": {
"ecosystem": "Ubuntu:25.10",
"name": "util-linux",
"purl": "pkg:deb/ubuntu/util-linux@2.41-4ubuntu4.2?arch=source\u0026distro=questing"
},
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.40.2-14ubuntu1",
"2.41-4ubuntu2",
"2.41-4ubuntu3",
"2.41-4ubuntu4",
"2.41-4ubuntu4.1",
"2.41-4ubuntu4.2"
]
},
{
"ecosystem_specific": {
"availability": "No subscription required",
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.41.3-3ubuntu2.2"
},
{
"binary_name": "eject",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "fdisk",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "lastlog2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libblkid1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "liblastlog2-2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libmount1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libpam-lastlog2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libuuid1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "login",
"binary_version": "1:4.16.0-2+really2.41.3-3ubuntu2.2"
},
{
"binary_name": "mount",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "rfkill",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.41.3-3ubuntu2.2"
}
]
},
"package": {
"ecosystem": "Ubuntu:26.04:LTS",
"name": "util-linux",
"purl": "pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=source\u0026distro=resolute"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.41.3-3ubuntu2.2"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.41-4ubuntu4",
"2.41.2-4ubuntu1",
"2.41.2-4ubuntu2",
"2.41.2-4ubuntu3",
"2.41.3-3ubuntu1",
"2.41.3-3ubuntu2"
]
}
],
"aliases": [],
"details": "[Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown]",
"id": "UBUNTU-CVE-2026-53612",
"modified": "2026-08-31T19:57:49Z",
"published": "2026-06-18T00:00:00Z",
"references": [
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2026-53612"
},
{
"type": "REPORT",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53612"
},
{
"type": "REPORT",
"url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh"
},
{
"type": "ADVISORY",
"url": "https://ubuntu.com/security/notices/USN-8702-1"
}
],
"related": [
"USN-8702-1"
],
"schema_version": "1.7.0",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
],
"upstream": [
"CVE-2026-53612"
]
}