{"schema_version":"1.7.2","id":"OESA-2026-3981","modified":"2026-09-20T13:23:47Z","published":"2026-09-20T13:23:47Z","upstream":["CVE-2026-53612","CVE-2026-53613","CVE-2026-53614","CVE-2026-76642","CVE-2026-78410"],"summary":"util-linux security update","details":"The util-linux package contains a random collection of files that implements some low-level basic linux utilities.\r\n\r\nSecurity Fix(es):\n\nCVE-2026-53612 has no publicly disclosed vulnerability details yet. It is only indexed by the Snyk data source. Details are pending disclosure.(CVE-2026-53612)\n\nWhen an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.(CVE-2026-53613)\n\nA flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root. Affected versions: util-linux v2.39.1 through v2.43-devel (current master).(CVE-2026-53614)\n\nutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.(CVE-2026-76642)\n\nA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.(CVE-2026-78410)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP3","name":"util-linux","purl":"pkg:rpm/openEuler/util-linux&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.39.1-44.oe2403sp3"}]}],"ecosystem_specific":{"aarch64":["libblkid-2.39.1-44.oe2403sp3.aarch64.rpm","libfdisk-2.39.1-44.oe2403sp3.aarch64.rpm","libmount-2.39.1-44.oe2403sp3.aarch64.rpm","libsmartcols-2.39.1-44.oe2403sp3.aarch64.rpm","libuuid-2.39.1-44.oe2403sp3.aarch64.rpm","python3-libmount-2.39.1-44.oe2403sp3.aarch64.rpm","util-linux-2.39.1-44.oe2403sp3.aarch64.rpm","util-linux-debuginfo-2.39.1-44.oe2403sp3.aarch64.rpm","util-linux-debugsource-2.39.1-44.oe2403sp3.aarch64.rpm","util-linux-devel-2.39.1-44.oe2403sp3.aarch64.rpm","util-linux-user-2.39.1-44.oe2403sp3.aarch64.rpm","uuidd-2.39.1-44.oe2403sp3.aarch64.rpm"],"noarch":["util-linux-help-2.39.1-44.oe2403sp3.noarch.rpm"],"src":["util-linux-2.39.1-44.oe2403sp3.src.rpm"],"x86_64":["libblkid-2.39.1-44.oe2403sp3.x86_64.rpm","libfdisk-2.39.1-44.oe2403sp3.x86_64.rpm","libmount-2.39.1-44.oe2403sp3.x86_64.rpm","libsmartcols-2.39.1-44.oe2403sp3.x86_64.rpm","libuuid-2.39.1-44.oe2403sp3.x86_64.rpm","python3-libmount-2.39.1-44.oe2403sp3.x86_64.rpm","util-linux-2.39.1-44.oe2403sp3.x86_64.rpm","util-linux-debuginfo-2.39.1-44.oe2403sp3.x86_64.rpm","util-linux-debugsource-2.39.1-44.oe2403sp3.x86_64.rpm","util-linux-devel-2.39.1-44.oe2403sp3.x86_64.rpm","util-linux-user-2.39.1-44.oe2403sp3.x86_64.rpm","uuidd-2.39.1-44.oe2403sp3.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3981"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53612"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53613"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53614"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"database_specific":{"severity":"High"}}
