Skip to main content
EPSS 0.2%top 91%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: 04/09/2026 (04/09/2026, 01:57:03 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs:

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64util-linux-main@aarch64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)Red Hat Enterprise Linux AppStream (v. 8)Red Hat Enterprise Linux BaseOS (v. 8)Red Hat Enterprise Linux CRB (v. 8)Red Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:08:53 UTC

Technical Analysis

CVE-2026-27456 is a TOCTOU race condition vulnerability in the util-linux mount program affecting Red Hat Hardened Images. When an /etc/fstab entry is configured with user,loop options, mount checks the file path with user permissions but opens it with root privileges, creating a brief window where an attacker can replace the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device containing a valid filesystem, gaining full read access to its contents. The vulnerability does not enable arbitrary code execution or memory corruption. Exploitation requires that the source path in /etc/fstab points to a directory writable by the attacker (e.g., the user's home directory). The advisory recommends removing the 'user' option from loop mounts or ensuring the source path is root-owned and not writable by unprivileged users. No explicit patch or fix release is confirmed in the vendor advisory content provided.

Potential Impact

The vulnerability allows local unprivileged users to gain unauthorized read access to root-owned files or block devices containing valid filesystems by exploiting a TOCTOU race condition in the mount program. This leads to information disclosure but does not allow privilege escalation, code execution, or memory corruption. The impact is limited to scenarios where /etc/fstab is configured with user,loop options and the source path is writable by the attacker. The severity is moderate due to the limited attack vector and impact scope.

Mitigation Recommendations

To mitigate this vulnerability, remove the 'user' option from any loop mounts in the /etc/fstab file or ensure that the source path points to a root-owned directory where unprivileged users do not have write permissions. No official patch status is confirmed in the advisory; therefore, users should apply these configuration changes to reduce risk. Monitor Red Hat advisories for any future official fixes or updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:1913
Cve Count
1

Threat ID: 6a1f4e86e29bf47b5007f22c

Added to database: 06/02/2026, 21:43:34 UTC

Last enriched: 08/16/2026, 18:08:53 UTC

Last updated: 09/12/2026, 22:33:31 UTC

Views: 162

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses