Search CVE reports


Toggle filters

1 – 10 of 34 results


CVE-2026-78410

Medium priority
Needs evaluation

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-78409

Medium priority
Needs evaluation

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-78408

Medium priority
Needs evaluation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-76642

Medium priority
Needs evaluation

[Unknown description]

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-13595

Medium priority

Some fixes available 3 of 8

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array....

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-53615

Medium priority

Some fixes available 3 of 8

[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-53614

Medium priority

Some fixes available 2 of 3

[Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)]

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-53613

Medium priority

Some fixes available 3 of 8

[Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-53612

Medium priority

Some fixes available 2 of 3

[Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown]

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-3184

Medium priority

Some fixes available 1 of 2

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit...

1 affected package

util-linux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
util-linux Fixed Not affected Not affected Not affected Not affected
Show less packages