Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13595

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Отчет

This Moderate severity heap use-after-free flaw in libblkid of util-linux could allow an attacker with local access to a system to cause a denial of service or potentially disclose limited information. The vulnerability is triggered when processing a specially crafted block device image, which libblkid automatically handles as root during hot-plug events via udev/udisks. This makes systems susceptible if untrusted block devices can be introduced.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxAffected
Red Hat Enterprise Linux 7util-linuxFix deferred
Red Hat Enterprise Linux 8util-linuxAffected
Red Hat Enterprise Linux 9util-linuxFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesutil-linux-main-2.42.2-1.hum1FixedRHSA-2026:2657317.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2494101util-linux: util-linux: heap use-after-free in libblkid nested partition probing

EPSS

Процентиль: 1%
0.0011
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 1 месяца назад

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

CVSS3: 6.8
nvd
около 1 месяца назад

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

CVSS3: 6.8
msrc
около 1 месяца назад

Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

CVSS3: 6.8
debian
около 1 месяца назад

A flaw was found in the libblkid library of util-linux. During nested ...

CVSS3: 6.8
github
около 1 месяца назад

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

EPSS

Процентиль: 1%
0.0011
Низкий

6.8 Medium

CVSS3