Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    BDU:2026-12870 (CVE-2026-53613)

    Vulnerability from fstec – Published: 2026-08-28 – Updated: 2026-09-17 – View on bdu.fstec.ru Exploit publicly available Fixed
    VLAI
    Title
    Уязвимость пакета служебных утилит командной строки Util-linux, связанная с недостаточной проверкой состояния совместно используемого ресурса, позволяющая нарушителю вызвать отказ в обслуживании
    Summary
    Уязвимость пакета служебных утилит командной строки Util-linux связана с недостаточной проверкой состояния совместно используемого ресурса. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании
    Severity
    Class
    Code vulnerability
    Status
    Confirmed by the vendor
    Exploitation
    Timing and state manipulation
    Incidents
    Being clarified
    Remediation
    Software update
    CWE
    • CWE-367 - Ситуация гонки Time-of-check Time-of-use (TOCTOU)
    Aliases
    Impacted products
    Vendors
    Red Hat, Inc., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра»
    Products
    Red Hat Enterprise Linux, Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat OpenShift Container Platform, util-linux
    Versions
    7 (Red Hat Enterprise Linux), 9 (Debian GNU/Linux), 8 (Red Hat Enterprise Linux), 10 (Debian GNU/Linux), 11 (Debian GNU/Linux), 12 (Debian GNU/Linux), 1.7 (Astra Linux Special Edition), 4 (Red Hat OpenShift Container Platform), 9 (Red Hat Enterprise Linux), 4.7 (Astra Linux Special Edition), 1.8 (Astra Linux Special Edition), 10 (Red Hat Enterprise Linux), 13 (Debian GNU/Linux), от 2.17 до 2.41.5 (util-linux), от 2.42.0 до 2.42.2 (util-linux)
    Product types
    Operating system, Application software
    Platforms
    Red Hat, Inc. Red Hat Enterprise Linux 7, Сообщество свободного программного обеспечения Debian GNU/Linux 9, Inc. Red Hat Enterprise Linux 8, Сообщество свободного программного обеспечения Debian GNU/Linux 10, Сообщество свободного программного обеспечения Debian GNU/Linux 11, Сообщество свободного программного обеспечения Debian GNU/Linux 12, ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7 (запись в едином реестре российских программ №369), Inc. Red Hat Enterprise Linux 9, ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7 ARM (запись в едином реестре российских программ №369), ООО «РусБИТех-Астра» Astra Linux Special Edition 1.8 (запись в едином реестре российских программ №369), Inc. Red Hat Enterprise Linux 10, Сообщество свободного программного обеспечения Debian GNU/Linux 13
    Mitigations
    В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года. Использование рекомендаций: Для Util-linux: https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g Для Debian GNU/Linux: https://security-tracker.debian.org/tracker/CVE-2026-53613 https://deb.freexian.com/extended-lts/tracker/CVE-2026-53613 Для ОС Astra Linux: обновить пакет util-linux до 2.33.1-0.1.deb10u1.astra9se7+ci2r3 или более высокой версии: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0820SE17 Для программных продуктов Red Hat, Inc.: https://access.redhat.com/security/cve/CVE-2026-53613 Для ОС Astra Linux: обновить пакет util-linux до 2.38.1-5+deb12u3+astra16 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0903SE18HF Для ОС Astra Linux: обновить пакет util-linux до 2.33.1-0.1.deb10u1.astra9se7+ci2r3 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47
    Credits
    Исследователь: Xinyao Hu

    {
      "CVSS 2.0": "AV:L/AC:H/Au:S/C:C/I:C/A:C",
      "CVSS 3.0": "AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "CVSS 4.0": null,
      "remediation_\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": null,
      "remediation_\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435": null,
      "\u0412\u0435\u043d\u0434\u043e\u0440 \u041f\u041e": "Red Hat, Inc., \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f, \u041e\u041e\u041e \u00ab\u0420\u0443\u0441\u0411\u0418\u0422\u0435\u0445-\u0410\u0441\u0442\u0440\u0430\u00bb",
      "\u0412\u0435\u0440\u0441\u0438\u044f \u041f\u041e": "7 (Red Hat Enterprise Linux), 9 (Debian GNU/Linux), 8 (Red Hat Enterprise Linux), 10 (Debian GNU/Linux), 11 (Debian GNU/Linux), 12 (Debian GNU/Linux), 1.7 (Astra Linux Special Edition), 4 (Red Hat OpenShift Container Platform), 9 (Red Hat Enterprise Linux), 4.7 (Astra Linux Special Edition), 1.8 (Astra Linux Special Edition), 10 (Red Hat Enterprise Linux), 13 (Debian GNU/Linux), \u043e\u0442 2.17 \u0434\u043e 2.41.5 (util-linux), \u043e\u0442 2.42.0 \u0434\u043e 2.42.2 (util-linux)",
      "\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u043c\u0435\u0440\u044b \u043f\u043e \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e": "\u0412 \u0443\u0441\u043b\u043e\u0432\u0438\u044f\u0445 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u044f \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0442\u044c\u0441\u044f \"\u0420\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0439 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0439 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c LINUX\", \u0438\u0437\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0445 \u0432 \u043c\u0435\u0442\u043e\u0434\u0438\u0447\u0435\u0441\u043a\u043e\u043c \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0435 \u0424\u0421\u0422\u042d\u041a \u0420\u043e\u0441\u0441\u0438\u0438, \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0451\u043d\u043d\u043e\u043c 25 \u0434\u0435\u043a\u0430\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430.\n\n\u0418\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0439:\n\u0414\u043b\u044f Util-linux:\nhttps://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g\n\n\u0414\u043b\u044f Debian GNU/Linux:\nhttps://security-tracker.debian.org/tracker/CVE-2026-53613\nhttps://deb.freexian.com/extended-lts/tracker/CVE-2026-53613\n\n\u0414\u043b\u044f \u041e\u0421 Astra Linux:\n\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442 util-linux \u0434\u043e 2.33.1-0.1.deb10u1.astra9se7+ci2r3 \u0438\u043b\u0438 \u0431\u043e\u043b\u0435\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0820SE17\n\n\u0414\u043b\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0445 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u043e\u0432 Red Hat, Inc.:\nhttps://access.redhat.com/security/cve/CVE-2026-53613\n\n\u0414\u043b\u044f \u041e\u0421 Astra Linux:\n\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442 util-linux \u0434\u043e 2.38.1-5+deb12u3+astra16 \u0438\u043b\u0438 \u0431\u043e\u043b\u0435\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0903SE18HF\n\n\u0414\u043b\u044f \u041e\u0421 Astra Linux:\n\u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c \u043f\u0430\u043a\u0435\u0442 util-linux \u0434\u043e 2.33.1-0.1.deb10u1.astra9se7+ci2r3 \u0438\u043b\u0438 \u0431\u043e\u043b\u0435\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47",
      "\u0414\u0430\u0442\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f": "16.06.2026",
      "\u0414\u0430\u0442\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f": "17.09.2026",
      "\u0414\u0430\u0442\u0430 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438": "28.08.2026",
      "\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": "BDU:2026-12870",
      "\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u044b \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "CVE-2026-53613",
      "\u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430",
      "\u041a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u0434\u0430",
      "\u041d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u041f\u041e": "Red Hat Enterprise Linux, Debian GNU/Linux, Astra Linux Special Edition (\u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u0435\u0434\u0438\u043d\u043e\u043c \u0440\u0435\u0435\u0441\u0442\u0440\u0435 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u2116369), Red Hat OpenShift Container Platform, util-linux",
      "\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u041e\u0421 \u0438 \u0442\u0438\u043f \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b": "Red Hat, Inc. Red Hat Enterprise Linux 7 , \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Debian GNU/Linux 9 , Red Hat, Inc. Red Hat Enterprise Linux 8 , \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Debian GNU/Linux 10 , \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Debian GNU/Linux 11 , \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Debian GNU/Linux 12 , \u041e\u041e\u041e \u00ab\u0420\u0443\u0441\u0411\u0418\u0422\u0435\u0445-\u0410\u0441\u0442\u0440\u0430\u00bb Astra Linux Special Edition 1.7  (\u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u0435\u0434\u0438\u043d\u043e\u043c \u0440\u0435\u0435\u0441\u0442\u0440\u0435 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u2116369), Red Hat, Inc. Red Hat Enterprise Linux 9 , \u041e\u041e\u041e \u00ab\u0420\u0443\u0441\u0411\u0418\u0422\u0435\u0445-\u0410\u0441\u0442\u0440\u0430\u00bb Astra Linux Special Edition 4.7 ARM (\u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u0435\u0434\u0438\u043d\u043e\u043c \u0440\u0435\u0435\u0441\u0442\u0440\u0435 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u2116369), \u041e\u041e\u041e \u00ab\u0420\u0443\u0441\u0411\u0418\u0422\u0435\u0445-\u0410\u0441\u0442\u0440\u0430\u00bb Astra Linux Special Edition 1.8  (\u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u0435\u0434\u0438\u043d\u043e\u043c \u0440\u0435\u0435\u0441\u0442\u0440\u0435 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u2116369), Red Hat, Inc. Red Hat Enterprise Linux 10 , \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Debian GNU/Linux 13 ",
      "\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0430\u043a\u0435\u0442\u0430 \u0441\u043b\u0443\u0436\u0435\u0431\u043d\u044b\u0445 \u0443\u0442\u0438\u043b\u0438\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 Util-linux, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u043e\u0439 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0430\u0440\u0443\u0448\u0438\u0442\u0435\u043b\u044e \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438",
      "\u041d\u0430\u043b\u0438\u0447\u0438\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430": "\u0421\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u0434\u043e\u0441\u0442\u0443\u043f\u0435",
      "\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u043e\u0448\u0438\u0431\u043a\u0438 CWE": "\u0421\u0438\u0442\u0443\u0430\u0446\u0438\u044f \u0433\u043e\u043d\u043a\u0438 Time-of-check Time-of-use (TOCTOU) (CWE-367)",
      "\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0430\u043a\u0435\u0442\u0430 \u0441\u043b\u0443\u0436\u0435\u0431\u043d\u044b\u0445 \u0443\u0442\u0438\u043b\u0438\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 Util-linux \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u043e\u0439 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u0430. \u042d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442\u044c \u043d\u0430\u0440\u0443\u0448\u0438\u0442\u0435\u043b\u044e \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438",
      "\u041f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": null,
      "\u041f\u0440\u043e\u0447\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f": "\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c: Xinyao Hu",
      "\u0421\u0432\u044f\u0437\u044c \u0441 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0430\u043c\u0438 \u0418\u0411": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
      "\u0421\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430",
      "\u0421\u043f\u043e\u0441\u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f": "\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f",
      "\u0421\u043f\u043e\u0441\u043e\u0431 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438": "\u041c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0441\u0440\u043e\u043a\u0430\u043c\u0438 \u0438 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c",
      "\u0421\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0438": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613\nhttps://security-tracker.debian.org/tracker/CVE-2026-53613\nhttps://github.com/util-linux/util-linux/commit/0b010025a0e429bc80355c94db86a843395d49e2\nhttps://github.com/util-linux/util-linux/commit/0d3d55975aa3492c62fd345eac38f41cd166c0b0\nhttps://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g\nhttps://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0820SE17\nhttps://deb.freexian.com/extended-lts/tracker/CVE-2026-53613\nhttps://access.redhat.com/security/cve/CVE-2026-53613\nhttps://github.com/mohamedjawady/CVE-2026-53613-poc\nhttps://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0903SE18HF\nhttps://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47",
      "\u0421\u0442\u0430\u0442\u0443\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u043c",
      "\u0422\u0438\u043f \u041f\u041e": "\u041e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u0430\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430, \u041f\u0440\u0438\u043a\u043b\u0430\u0434\u043d\u043e\u0435 \u041f\u041e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c",
      "\u0422\u0438\u043f \u043e\u0448\u0438\u0431\u043a\u0438 CWE": "CWE-367",
      "\u0423\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0421\u0440\u0435\u0434\u043d\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (\u0431\u0430\u0437\u043e\u0432\u0430\u044f \u043e\u0446\u0435\u043d\u043a\u0430 CVSS 2.0 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 6)\n\u0412\u044b\u0441\u043e\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (\u0431\u0430\u0437\u043e\u0432\u0430\u044f \u043e\u0446\u0435\u043d\u043a\u0430 CVSS 3.1 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 7)"
    }

    BELL-CVE-2026-53613 (CVE-2026-53613)

    Vulnerability from osv_bellsoft – Published: 2026-06-19 06:12 – Updated: 2026-08-05 06:01 – Source website
    VLAI

    {
      "affected": [
        {
          "package": {
            "ecosystem": "Alpaquita:25",
            "name": "util-linux",
            "purl": "pkg:apk/alpaquita/util-linux?arch=source\u0026distro=25"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.41-r6"
                },
                {
                  "fixed": "2.41.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "Alpaquita:stream",
            "name": "util-linux",
            "purl": "pkg:apk/alpaquita/util-linux?arch=source\u0026distro=stream"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.39-r14"
                },
                {
                  "fixed": "2.42.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "BellSoft Hardened Containers:25",
            "name": "util-linux",
            "purl": "pkg:apk/bellsoft-hardened-containers/util-linux?arch=source\u0026distro=25"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.41-r6"
                },
                {
                  "fixed": "2.41.5-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "BellSoft Hardened Containers:stream",
            "name": "util-linux",
            "purl": "pkg:apk/bellsoft-hardened-containers/util-linux?arch=source\u0026distro=stream"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.39-r14"
                },
                {
                  "fixed": "2.42.2-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "id": "BELL-CVE-2026-53613",
      "modified": "2026-08-05T06:01:24.72825Z",
      "published": "2026-06-19T06:12:42.929127Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://docs.bell-sw.com/security/cves/CVE-2026-53613"
        }
      ],
      "schema_version": "1.7.4",
      "upstream": [
        "CVE-2026-53613"
      ]
    }

    CERTFR-2026-AVI-1068

    Vulnerability from certfr_avis - Published: 2026-08-21 - Updated: 2026-08-21

    De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Debian Debian Debian trixie versions antérieures à 2.41.5-0+deb13u1
    References
    Bulletin de sécurité Debian msg00353 2026-08-14 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Debian trixie versions ant\u00e9rieures \u00e0 2.41.5-0+deb13u1",
          "product": {
            "name": "Debian",
            "vendor": {
              "name": "Debian",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-53613",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
        },
        {
          "name": "CVE-2026-53614",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53614"
        },
        {
          "name": "CVE-2026-27456",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        },
        {
          "name": "CVE-2026-13595",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        },
        {
          "name": "CVE-2026-53612",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53612"
        }
      ],
      "initial_release_date": "2026-08-21T00:00:00",
      "last_revision_date": "2026-08-21T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1068",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-21T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de Debian. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de Debian",
      "vendor_advisories": [
        {
          "published_at": "2026-08-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Debian msg00353",
          "url": "https://lists.debian.org/debian-security-announce/2026/msg00353.html"
        }
      ]
    }

    OESA-2026-3978 (CVE-2026-53613)

    Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source website
    VLAI
    Summary
    util-linux security update
    Details

    The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

    Security Fix(es):

    When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "libblkid-2.35.2-35.oe2003sp4.aarch64.rpm",
              "libfdisk-2.35.2-35.oe2003sp4.aarch64.rpm",
              "libmount-2.35.2-35.oe2003sp4.aarch64.rpm",
              "libsmartcols-2.35.2-35.oe2003sp4.aarch64.rpm",
              "libuuid-2.35.2-35.oe2003sp4.aarch64.rpm",
              "python-libmount-2.35.2-35.oe2003sp4.aarch64.rpm",
              "util-linux-2.35.2-35.oe2003sp4.aarch64.rpm",
              "util-linux-debuginfo-2.35.2-35.oe2003sp4.aarch64.rpm",
              "util-linux-debugsource-2.35.2-35.oe2003sp4.aarch64.rpm",
              "util-linux-devel-2.35.2-35.oe2003sp4.aarch64.rpm",
              "util-linux-user-2.35.2-35.oe2003sp4.aarch64.rpm",
              "uuidd-2.35.2-35.oe2003sp4.aarch64.rpm"
            ],
            "noarch": [
              "util-linux-help-2.35.2-35.oe2003sp4.noarch.rpm"
            ],
            "src": [
              "util-linux-2.35.2-35.oe2003sp4.src.rpm"
            ],
            "x86_64": [
              "libblkid-2.35.2-35.oe2003sp4.x86_64.rpm",
              "libfdisk-2.35.2-35.oe2003sp4.x86_64.rpm",
              "libmount-2.35.2-35.oe2003sp4.x86_64.rpm",
              "libsmartcols-2.35.2-35.oe2003sp4.x86_64.rpm",
              "libuuid-2.35.2-35.oe2003sp4.x86_64.rpm",
              "python-libmount-2.35.2-35.oe2003sp4.x86_64.rpm",
              "util-linux-2.35.2-35.oe2003sp4.x86_64.rpm",
              "util-linux-debuginfo-2.35.2-35.oe2003sp4.x86_64.rpm",
              "util-linux-debugsource-2.35.2-35.oe2003sp4.x86_64.rpm",
              "util-linux-devel-2.35.2-35.oe2003sp4.x86_64.rpm",
              "util-linux-user-2.35.2-35.oe2003sp4.x86_64.rpm",
              "uuidd-2.35.2-35.oe2003sp4.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:20.03-LTS-SP4",
            "name": "util-linux",
            "purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-20.03-LTS-SP4"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.35.2-35.oe2003sp4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
      "id": "OESA-2026-3978",
      "modified": "2026-09-20T13:23:45Z",
      "published": "2026-09-20T13:23:45Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3978"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "util-linux security update",
      "upstream": [
        "CVE-2026-53613",
        "CVE-2026-78410"
      ]
    }

    OESA-2026-3979 (CVE-2026-53613)

    Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source website
    VLAI
    Summary
    util-linux security update
    Details

    The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

    Security Fix(es):

    When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "libblkid-2.37.2-56.oe2203sp4.aarch64.rpm",
              "libfdisk-2.37.2-56.oe2203sp4.aarch64.rpm",
              "libmount-2.37.2-56.oe2203sp4.aarch64.rpm",
              "libsmartcols-2.37.2-56.oe2203sp4.aarch64.rpm",
              "libuuid-2.37.2-56.oe2203sp4.aarch64.rpm",
              "python3-libmount-2.37.2-56.oe2203sp4.aarch64.rpm",
              "util-linux-2.37.2-56.oe2203sp4.aarch64.rpm",
              "util-linux-debuginfo-2.37.2-56.oe2203sp4.aarch64.rpm",
              "util-linux-debugsource-2.37.2-56.oe2203sp4.aarch64.rpm",
              "util-linux-devel-2.37.2-56.oe2203sp4.aarch64.rpm",
              "util-linux-user-2.37.2-56.oe2203sp4.aarch64.rpm",
              "uuidd-2.37.2-56.oe2203sp4.aarch64.rpm"
            ],
            "noarch": [
              "util-linux-help-2.37.2-56.oe2203sp4.noarch.rpm"
            ],
            "src": [
              "util-linux-2.37.2-56.oe2203sp4.src.rpm"
            ],
            "x86_64": [
              "libblkid-2.37.2-56.oe2203sp4.x86_64.rpm",
              "libfdisk-2.37.2-56.oe2203sp4.x86_64.rpm",
              "libmount-2.37.2-56.oe2203sp4.x86_64.rpm",
              "libsmartcols-2.37.2-56.oe2203sp4.x86_64.rpm",
              "libuuid-2.37.2-56.oe2203sp4.x86_64.rpm",
              "python3-libmount-2.37.2-56.oe2203sp4.x86_64.rpm",
              "util-linux-2.37.2-56.oe2203sp4.x86_64.rpm",
              "util-linux-debuginfo-2.37.2-56.oe2203sp4.x86_64.rpm",
              "util-linux-debugsource-2.37.2-56.oe2203sp4.x86_64.rpm",
              "util-linux-devel-2.37.2-56.oe2203sp4.x86_64.rpm",
              "util-linux-user-2.37.2-56.oe2203sp4.x86_64.rpm",
              "uuidd-2.37.2-56.oe2203sp4.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:22.03-LTS-SP4",
            "name": "util-linux",
            "purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-22.03-LTS-SP4"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.37.2-56.oe2203sp4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
      "id": "OESA-2026-3979",
      "modified": "2026-09-20T13:23:46Z",
      "published": "2026-09-20T13:23:46Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3979"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "util-linux security update",
      "upstream": [
        "CVE-2026-53613",
        "CVE-2026-78410"
      ]
    }

    OESA-2026-3980 (CVE-2026-53612)

    Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source website
    VLAI
    Summary
    util-linux security update
    Details

    The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

    Security Fix(es):

    CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)

    When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)

    A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "libblkid-2.39.1-44.oe2403sp1.aarch64.rpm",
              "libfdisk-2.39.1-44.oe2403sp1.aarch64.rpm",
              "libmount-2.39.1-44.oe2403sp1.aarch64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp1.aarch64.rpm",
              "libuuid-2.39.1-44.oe2403sp1.aarch64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp1.aarch64.rpm",
              "util-linux-2.39.1-44.oe2403sp1.aarch64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp1.aarch64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp1.aarch64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp1.aarch64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp1.aarch64.rpm",
              "uuidd-2.39.1-44.oe2403sp1.aarch64.rpm"
            ],
            "noarch": [
              "util-linux-help-2.39.1-44.oe2403sp1.noarch.rpm"
            ],
            "src": [
              "util-linux-2.39.1-44.oe2403sp1.src.rpm"
            ],
            "x86_64": [
              "libblkid-2.39.1-44.oe2403sp1.x86_64.rpm",
              "libfdisk-2.39.1-44.oe2403sp1.x86_64.rpm",
              "libmount-2.39.1-44.oe2403sp1.x86_64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp1.x86_64.rpm",
              "libuuid-2.39.1-44.oe2403sp1.x86_64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp1.x86_64.rpm",
              "util-linux-2.39.1-44.oe2403sp1.x86_64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp1.x86_64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp1.x86_64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp1.x86_64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp1.x86_64.rpm",
              "uuidd-2.39.1-44.oe2403sp1.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP1",
            "name": "util-linux",
            "purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP1"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.39.1-44.oe2403sp1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
      "id": "OESA-2026-3980",
      "modified": "2026-09-20T13:23:47Z",
      "published": "2026-09-20T13:23:47Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3980"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "util-linux security update",
      "upstream": [
        "CVE-2026-53612",
        "CVE-2026-53613",
        "CVE-2026-53614",
        "CVE-2026-78410"
      ]
    }

    OESA-2026-3981 (CVE-2026-53612)

    Vulnerability from osv_openeuler – Published: 2026-09-20 13:23 – Updated: 2026-09-20 13:23 – Source website
    VLAI
    Summary
    util-linux security update
    Details

    The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

    Security Fix(es):

    CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)

    When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)

    A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)

    util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.(CVE-2026-76642)

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "libblkid-2.39.1-44.oe2403sp3.aarch64.rpm",
              "libfdisk-2.39.1-44.oe2403sp3.aarch64.rpm",
              "libmount-2.39.1-44.oe2403sp3.aarch64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp3.aarch64.rpm",
              "libuuid-2.39.1-44.oe2403sp3.aarch64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp3.aarch64.rpm",
              "util-linux-2.39.1-44.oe2403sp3.aarch64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp3.aarch64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp3.aarch64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp3.aarch64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp3.aarch64.rpm",
              "uuidd-2.39.1-44.oe2403sp3.aarch64.rpm"
            ],
            "noarch": [
              "util-linux-help-2.39.1-44.oe2403sp3.noarch.rpm"
            ],
            "src": [
              "util-linux-2.39.1-44.oe2403sp3.src.rpm"
            ],
            "x86_64": [
              "libblkid-2.39.1-44.oe2403sp3.x86_64.rpm",
              "libfdisk-2.39.1-44.oe2403sp3.x86_64.rpm",
              "libmount-2.39.1-44.oe2403sp3.x86_64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp3.x86_64.rpm",
              "libuuid-2.39.1-44.oe2403sp3.x86_64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp3.x86_64.rpm",
              "util-linux-2.39.1-44.oe2403sp3.x86_64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp3.x86_64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp3.x86_64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp3.x86_64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp3.x86_64.rpm",
              "uuidd-2.39.1-44.oe2403sp3.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP3",
            "name": "util-linux",
            "purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP3"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.39.1-44.oe2403sp3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.(CVE-2026-76642)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
      "id": "OESA-2026-3981",
      "modified": "2026-09-20T13:23:47Z",
      "published": "2026-09-20T13:23:47Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3981"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76642"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "util-linux security update",
      "upstream": [
        "CVE-2026-53612",
        "CVE-2026-53613",
        "CVE-2026-53614",
        "CVE-2026-76642",
        "CVE-2026-78410"
      ]
    }

    OESA-2026-4073 (CVE-2026-53612)

    Vulnerability from osv_openeuler – Published: 2026-09-25 01:28 – Updated: 2026-09-25 01:28 – Source website
    VLAI
    Summary
    util-linux security update
    Details

    The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

    Security Fix(es):

    CVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)

    When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)

    A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "libblkid-2.39.1-44.oe2403sp4.aarch64.rpm",
              "libfdisk-2.39.1-44.oe2403sp4.aarch64.rpm",
              "libmount-2.39.1-44.oe2403sp4.aarch64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp4.aarch64.rpm",
              "libuuid-2.39.1-44.oe2403sp4.aarch64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp4.aarch64.rpm",
              "util-linux-2.39.1-44.oe2403sp4.aarch64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp4.aarch64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp4.aarch64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp4.aarch64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp4.aarch64.rpm",
              "uuidd-2.39.1-44.oe2403sp4.aarch64.rpm"
            ],
            "noarch": [
              "util-linux-help-2.39.1-44.oe2403sp4.noarch.rpm"
            ],
            "src": [
              "util-linux-2.39.1-44.oe2403sp4.src.rpm"
            ],
            "x86_64": [
              "libblkid-2.39.1-44.oe2403sp4.x86_64.rpm",
              "libfdisk-2.39.1-44.oe2403sp4.x86_64.rpm",
              "libmount-2.39.1-44.oe2403sp4.x86_64.rpm",
              "libsmartcols-2.39.1-44.oe2403sp4.x86_64.rpm",
              "libuuid-2.39.1-44.oe2403sp4.x86_64.rpm",
              "python3-libmount-2.39.1-44.oe2403sp4.x86_64.rpm",
              "util-linux-2.39.1-44.oe2403sp4.x86_64.rpm",
              "util-linux-debuginfo-2.39.1-44.oe2403sp4.x86_64.rpm",
              "util-linux-debugsource-2.39.1-44.oe2403sp4.x86_64.rpm",
              "util-linux-devel-2.39.1-44.oe2403sp4.x86_64.rpm",
              "util-linux-user-2.39.1-44.oe2403sp4.x86_64.rpm",
              "uuidd-2.39.1-44.oe2403sp4.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP4",
            "name": "util-linux",
            "purl": "pkg:rpm/openEuler/util-linux\u0026distro=openEuler-24.03-LTS-SP4"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.39.1-44.oe2403sp4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)",
      "id": "OESA-2026-4073",
      "modified": "2026-09-25T01:28:04Z",
      "published": "2026-09-25T01:28:04Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4073"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53612"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53614"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78410"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "util-linux security update",
      "upstream": [
        "CVE-2026-53612",
        "CVE-2026-53613",
        "CVE-2026-53614",
        "CVE-2026-78410"
      ]
    }

    OPENSUSE-SU-2026:11408-1

    Vulnerability from csaf_opensuse - Published: 2026-07-29 00:00 - Updated: 2026-09-26 08:34
    Summary
    libblkid-devel-2.42.2-1.1 on GA media
    Severity
    Moderate
    Scope
    4 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 108 products
    Open the full advisory

    OPENSUSE-SU-2026:21905-1

    Vulnerability from csaf_opensuse - Published: 2026-09-22 07:23 - Updated: 2026-09-26 08:35
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    8 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 94 products
    Open the full advisory

    SUSE-SU-2026:23250-1

    Vulnerability from csaf_suse - Published: 2026-08-21 14:17 - Updated: 2026-09-26 08:30
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    5 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 21 products
    Open the full advisory

    SUSE-SU-2026:23255-1

    Vulnerability from csaf_suse - Published: 2026-08-24 15:02 - Updated: 2026-09-26 08:30
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    5 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 36 products
    Open the full advisory

    SUSE-SU-2026:23861-1

    Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-27 11:06
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    8 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 186 products
    Open the full advisory

    SUSE-SU-2026:23870-1

    Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-27 11:06
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    8 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 186 products
    Open the full advisory

    SUSE-SU-2026:23884-1

    Vulnerability from csaf_suse - Published: 2026-09-22 07:23 - Updated: 2026-09-30 11:15
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    8 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 36 products
    Open the full advisory

    SUSE-SU-2026:3685-1

    Vulnerability from csaf_suse - Published: 2026-08-21 18:24 - Updated: 2026-09-26 08:32
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    5 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 207 products
    Open the full advisory

    SUSE-SU-2026:3813-1

    Vulnerability from csaf_suse - Published: 2026-08-26 10:55 - Updated: 2026-09-26 08:33
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    3 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 326 products
    Open the full advisory

    SUSE-SU-2026:4296-1

    Vulnerability from csaf_suse - Published: 2026-09-23 07:56 - Updated: 2026-09-26 08:34
    Summary
    Security update for util-linux
    Severity
    Important
    Scope
    3 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Recommended: 253 products
    Open the full advisory

    UBUNTU-CVE-2026-53613 (CVE-2026-53613)

    Vulnerability from osv_ubuntu – Published: 2026-06-18 00:00 – Updated: 2026-08-31 19:57 – Source website
    VLAI
    Details

    [Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]

    Severity
    N/A (UNKNOWN)

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.20.1-5.1ubuntu20.9"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:14.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.20.1-5.1ubuntu20.9?arch=source\u0026distro=trusty"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.20.1-5.1ubuntu9",
            "2.20.1-5.1ubuntu10",
            "2.20.1-5.1ubuntu11",
            "2.20.1-5.1ubuntu12",
            "2.20.1-5.1ubuntu13",
            "2.20.1-5.1ubuntu14",
            "2.20.1-5.1ubuntu15",
            "2.20.1-5.1ubuntu16",
            "2.20.1-5.1ubuntu17",
            "2.20.1-5.1ubuntu18",
            "2.20.1-5.1ubuntu19",
            "2.20.1-5.1ubuntu20",
            "2.20.1-5.1ubuntu20.1",
            "2.20.1-5.1ubuntu20.2",
            "2.20.1-5.1ubuntu20.3",
            "2.20.1-5.1ubuntu20.4",
            "2.20.1-5.1ubuntu20.6",
            "2.20.1-5.1ubuntu20.7",
            "2.20.1-5.1ubuntu20.9"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.27.1-6ubuntu3.10+esm2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:16.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.27.1-6ubuntu3.10+esm2?arch=source\u0026distro=esm-infra/xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.26.2-6ubuntu3",
            "2.27-3ubuntu1",
            "2.27.1-1ubuntu2",
            "2.27.1-1ubuntu3",
            "2.27.1-1ubuntu4",
            "2.27.1-3ubuntu1",
            "2.27.1-4ubuntu1",
            "2.27.1-6ubuntu1",
            "2.27.1-6ubuntu2",
            "2.27.1-6ubuntu3",
            "2.27.1-6ubuntu3.1",
            "2.27.1-6ubuntu3.2",
            "2.27.1-6ubuntu3.3",
            "2.27.1-6ubuntu3.4",
            "2.27.1-6ubuntu3.6",
            "2.27.1-6ubuntu3.7",
            "2.27.1-6ubuntu3.8",
            "2.27.1-6ubuntu3.9",
            "2.27.1-6ubuntu3.10",
            "2.27.1-6ubuntu3.10+esm2"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "setpriv",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.31.1-0.4ubuntu3.7"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:18.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.31.1-0.4ubuntu3.7?arch=source\u0026distro=bionic"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.30.1-0ubuntu4",
            "2.30.2-0.1ubuntu1",
            "2.30.2-0.1ubuntu2",
            "2.30.2-0.1ubuntu3",
            "2.31.1-0.4ubuntu2",
            "2.31.1-0.4ubuntu3",
            "2.31.1-0.4ubuntu3.1",
            "2.31.1-0.4ubuntu3.2",
            "2.31.1-0.4ubuntu3.3",
            "2.31.1-0.4ubuntu3.4",
            "2.31.1-0.4ubuntu3.5",
            "2.31.1-0.4ubuntu3.6",
            "2.31.1-0.4ubuntu3.7"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.34-0.1ubuntu9.6+esm1"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:20.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.6+esm1?arch=source\u0026distro=esm-infra/focal"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.34-0.1ubuntu2",
            "2.34-0.1ubuntu4",
            "2.34-0.1ubuntu5",
            "2.34-0.1ubuntu6",
            "2.34-0.1ubuntu7",
            "2.34-0.1ubuntu8",
            "2.34-0.1ubuntu9",
            "2.34-0.1ubuntu9.1",
            "2.34-0.1ubuntu9.3",
            "2.34-0.1ubuntu9.4",
            "2.34-0.1ubuntu9.5",
            "2.34-0.1ubuntu9.6",
            "2.34-0.1ubuntu9.6+esm1"
          ]
        },
        {
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "bsdextrautils",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "eject",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.37.2-4ubuntu3.6"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.37.2-4ubuntu3.6"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:22.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.37.2-4ubuntu3.6?arch=source\u0026distro=jammy"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.37.2-4ubuntu3.6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.36.1-8ubuntu1",
            "2.37.2-4ubuntu1",
            "2.37.2-4ubuntu2",
            "2.37.2-4ubuntu3",
            "2.37.2-4ubuntu3.3",
            "2.37.2-4ubuntu3.4",
            "2.37.2-4ubuntu3.5"
          ]
        },
        {
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "bsdextrautils",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "eject",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "util-linux-extra",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.39.3-9ubuntu6.6"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.39.3-9ubuntu6.6"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:24.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=source\u0026distro=noble"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.39.3-9ubuntu6.6"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.39.1-4ubuntu2",
            "2.39.2-6ubuntu1",
            "2.39.3-6ubuntu2",
            "2.39.3-9ubuntu2",
            "2.39.3-9ubuntu4",
            "2.39.3-9ubuntu6",
            "2.39.3-9ubuntu6.1",
            "2.39.3-9ubuntu6.2",
            "2.39.3-9ubuntu6.3",
            "2.39.3-9ubuntu6.4",
            "2.39.3-9ubuntu6.5"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "bsdextrautils",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.41-4ubuntu4.2"
              },
              {
                "binary_name": "eject",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "lastlog2",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "liblastlog2-2",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libpam-lastlog2",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "login",
                "binary_version": "1:4.16.0-2+really2.41-4ubuntu4.2"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "util-linux-extra",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.41-4ubuntu4.2"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.41-4ubuntu4.2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:25.10",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.41-4ubuntu4.2?arch=source\u0026distro=questing"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.40.2-14ubuntu1",
            "2.41-4ubuntu2",
            "2.41-4ubuntu3",
            "2.41-4ubuntu4",
            "2.41-4ubuntu4.1",
            "2.41-4ubuntu4.2"
          ]
        },
        {
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "bsdextrautils",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "bsdutils",
                "binary_version": "1:2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "eject",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "fdisk",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "lastlog2",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libblkid1",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libfdisk1",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "liblastlog2-2",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libmount1",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libpam-lastlog2",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libsmartcols1",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "libuuid1",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "login",
                "binary_version": "1:4.16.0-2+really2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "mount",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "rfkill",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "util-linux",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "util-linux-extra",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "util-linux-locales",
                "binary_version": "2.41.3-3ubuntu2.2"
              },
              {
                "binary_name": "uuid-runtime",
                "binary_version": "2.41.3-3ubuntu2.2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:26.04:LTS",
            "name": "util-linux",
            "purl": "pkg:deb/ubuntu/util-linux@2.41.3-3ubuntu2.2?arch=source\u0026distro=resolute"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2.41.3-3ubuntu2.2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.41-4ubuntu4",
            "2.41.2-4ubuntu1",
            "2.41.2-4ubuntu2",
            "2.41.2-4ubuntu3",
            "2.41.3-3ubuntu1",
            "2.41.3-3ubuntu2"
          ]
        }
      ],
      "aliases": [],
      "details": "[Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]",
      "id": "UBUNTU-CVE-2026-53613",
      "modified": "2026-08-31T19:57:49Z",
      "published": "2026-06-18T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2026-53613"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
        },
        {
          "type": "REPORT",
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g"
        },
        {
          "type": "ADVISORY",
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        }
      ],
      "related": [
        "USN-8702-1"
      ],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "medium",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2026-53613"
      ]
    }

    WID-SEC-W-2026-2938

    Vulnerability from csaf_certbund - Published: 2026-08-19 22:00 - Updated: 2026-09-29 22:00
    Summary
    util-linux: Mehrere Schwachstellen
    Severity
    Hoch
    Scope
    4 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Known affected: 4 products Last affected: 1 product
    Open the full advisory

    WID-SEC-W-2026-3642

    Vulnerability from csaf_certbund - Published: 2026-09-29 22:00 - Updated: 2026-09-29 22:00
    Summary
    Meinberg LANTIME: Mehrere Schwachstellen
    Severity
    Hoch
    Scope
    39 vulnerabilities in this advisory, including CVE-2026-53613.
    CVE-2026-53613
    Known affected: 1 product
    Open the full advisory