Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78409

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

Отчет

Affected versions: util-linux v2.42 through v2.42.2. The Linux >= 6.15 detached-tree X-mount.subdir fast path was introduced in ae19f7546ccb (2025-04-15) and first released in v2.42. Earlier releases, including v2.40 and v2.41, are not affected. Restricted-user SUID mount(8) reproduction also requires Linux >= 6.15. Fixed in v2.41.6 and v2.42.3.

Меры по смягчению последствий

Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab entries that specify X-mount.subdir.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxNot affected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-runtimeNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-sdkNot affected
Red Hat Enterprise Linux 9util-linuxNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesutil-linux-main-2.42.2-3.4.hum1FixedRHSA-2026:6316203.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2522607util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks

EPSS

Процентиль: 2%
0.00124
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
15 дней назад

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

CVSS3: 7
nvd
15 дней назад

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

CVSS3: 7
debian
15 дней назад

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 ...

EPSS

Процентиль: 2%
0.00124
Низкий

7 High

CVSS3