Threats Tagged 'cve-2026-13595'
View all threats tagged with 'cve-2026-13595'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-13595'
Click on any threat for detailed analysis and mitigation recommendations
0 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). Join the discussion | GCVE Database | 09/22/2026, 07:23:43 UTC Added: 07/08/2026, 13:21:33 UTC |
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service. Join the discussion | CVE Database V5 | 06/29/2026, 08:06:09 UTC Added: 06/29/2026, 08:51:47 UTC |
Showing 1 to 2 of 2 results