Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76642

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7.8

Описание

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

When an external mount. helper runs but exits with a nonzero status, libmount still treats the helper invocation as successful and runs privileged post-mount hooks. A local unprivileged user with an /etc/fstab entry that uses the user option together with X-mount.idmap or X-mount.owner/group/mode can cause those hooks to clone or re-own the underlying filesystem after the helper fails, leading to local privilege escalation.

Отчет

Affected versions: util-linux v2.39 through v2.42.2. Fixed in v2.41.6 and v2.42.3.

Меры по смягчению последствий

Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, avoid combining the user (or users) fstab option with X-mount.idmap or X-mount.owner/group/mode on entries that invoke an external mount. helper. Administrators can also remove or restrict user-mountable fstab entries that specify those X-mount.* options.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxAffected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-runtimeNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-sdkNot affected
Red Hat Enterprise Linux 9util-linuxNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesutil-linux-main-2.42.2-3.4.hum1FixedRHSA-2026:6316203.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-390
https://bugzilla.redhat.com/show_bug.cgi?id=2521999util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
14 дней назад

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

CVSS3: 7.8
nvd
14 дней назад

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

msrc
1 день назад

util-linux libmount Privilege Escalation via Failed Mount Helper

CVSS3: 7.8
debian
14 дней назад

util-linux versions through 2.41.5 and 2.42.2 fail to check mount help ...

CVSS3: 7.8
fstec
16 дней назад

Уязвимость пакета служебных утилит командной строки Util-linux, связанная с недостатками обработки ошибочных ситуаций, позволяющая нарушителю повысить свои привилегии

7.8 High

CVSS3