Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53613

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 7

Описание

When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.

Отчет

Affected versions: util-linux v2.17 through v2.43-devel.

Меры по смягчению последствий

Fixed in v2.41.5 and v2.42.2. For restricted user mounts, reject target paths where any ancestor directory is writable by the calling user. Verify the complete ancestor chain integrity before executing the mount syscall.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxAffected
Red Hat Enterprise Linux 7util-linuxAffected
Red Hat Enterprise Linux 8util-linuxAffected
Red Hat Enterprise Linux 9rhel8/flatpak-runtimeAffected
Red Hat Enterprise Linux 9rhel8/flatpak-sdkAffected
Red Hat Enterprise Linux 9util-linuxAffected
Red Hat Hardened Imagesutil-linuxNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2519646util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path

7 High

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

[Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]

debian

[Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]

CVSS3: 7
fstec
3 месяца назад

Уязвимость пакета служебных утилит командной строки Util-linux, связанная с недостаточной проверкой состояния совместно используемого ресурса, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
26 дней назад

Security update for util-linux

suse-cvrf
26 дней назад

Security update for util-linux

7 High

CVSS3