Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs:
AI Analysis
Technical Summary
CVE-2026-27456 is a TOCTOU race condition vulnerability in the util-linux mount program affecting Red Hat Hardened Images. When an /etc/fstab entry is configured with user,loop options, mount checks the file path with user permissions but opens it with root privileges, creating a brief window where an attacker can replace the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device containing a valid filesystem, gaining full read access to its contents. The vulnerability does not enable arbitrary code execution or memory corruption. Exploitation requires that the source path in /etc/fstab points to a directory writable by the attacker (e.g., the user's home directory). The advisory recommends removing the 'user' option from loop mounts or ensuring the source path is root-owned and not writable by unprivileged users. No explicit patch or fix release is confirmed in the vendor advisory content provided.
Potential Impact
The vulnerability allows local unprivileged users to gain unauthorized read access to root-owned files or block devices containing valid filesystems by exploiting a TOCTOU race condition in the mount program. This leads to information disclosure but does not allow privilege escalation, code execution, or memory corruption. The impact is limited to scenarios where /etc/fstab is configured with user,loop options and the source path is writable by the attacker. The severity is moderate due to the limited attack vector and impact scope.
Mitigation Recommendations
To mitigate this vulnerability, remove the 'user' option from any loop mounts in the /etc/fstab file or ensure that the source path points to a root-owned directory where unprivileged users do not have write permissions. No official patch status is confirmed in the advisory; therefore, users should apply these configuration changes to reduce risk. Monitor Red Hat advisories for any future official fixes or updates.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs:
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27456 is a TOCTOU race condition vulnerability in the util-linux mount program affecting Red Hat Hardened Images. When an /etc/fstab entry is configured with user,loop options, mount checks the file path with user permissions but opens it with root privileges, creating a brief window where an attacker can replace the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device containing a valid filesystem, gaining full read access to its contents. The vulnerability does not enable arbitrary code execution or memory corruption. Exploitation requires that the source path in /etc/fstab points to a directory writable by the attacker (e.g., the user's home directory). The advisory recommends removing the 'user' option from loop mounts or ensuring the source path is root-owned and not writable by unprivileged users. No explicit patch or fix release is confirmed in the vendor advisory content provided.
Potential Impact
The vulnerability allows local unprivileged users to gain unauthorized read access to root-owned files or block devices containing valid filesystems by exploiting a TOCTOU race condition in the mount program. This leads to information disclosure but does not allow privilege escalation, code execution, or memory corruption. The impact is limited to scenarios where /etc/fstab is configured with user,loop options and the source path is writable by the attacker. The severity is moderate due to the limited attack vector and impact scope.
Mitigation Recommendations
To mitigate this vulnerability, remove the 'user' option from any loop mounts in the /etc/fstab file or ensure that the source path points to a root-owned directory where unprivileged users do not have write permissions. No official patch status is confirmed in the advisory; therefore, users should apply these configuration changes to reduce risk. Monitor Red Hat advisories for any future official fixes or updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:1913
- Cve Count
- 1
Threat ID: 6a1f4e86e29bf47b5007f22c
Added to database: 06/02/2026, 21:43:34 UTC
Last enriched: 08/16/2026, 18:08:53 UTC
Last updated: 09/12/2026, 22:33:31 UTC
Views: 162
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.