Описание
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
Отчет
Affected versions: util-linux v2.42 through v2.42.2. The Linux >= 6.15 detached-tree X-mount.subdir fast path was introduced in ae19f7546ccb (2025-04-15) and first released in v2.42. Earlier releases, including v2.40 and v2.41, are not affected. Restricted-user SUID mount(8) reproduction also requires Linux >= 6.15. Fixed in v2.41.6 and v2.42.3.
Меры по смягчению последствий
Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab entries that specify X-mount.subdir.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | util-linux | Not affected | ||
| Red Hat Enterprise Linux 7 | util-linux | Not affected | ||
| Red Hat Enterprise Linux 8 | util-linux | Not affected | ||
| Red Hat Enterprise Linux 9 | rhel8/flatpak-runtime | Not affected | ||
| Red Hat Enterprise Linux 9 | rhel8/flatpak-sdk | Not affected | ||
| Red Hat Enterprise Linux 9 | util-linux | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Hardened Images | util-linux-main-2.42.2-3.4.hum1 | Fixed | RHSA-2026:63162 | 03.09.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 ...
EPSS
7 High
CVSS3