Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78410

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

Отчет

Affected versions: util-linux v2.39 through v2.42.2. X-mount.owner/group/mode was introduced in v2.39; earlier releases are not affected. Fixed in v2.41.6 and v2.42.3.

Меры по смягчению последствий

Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab bind or rbind entries that also specify X-mount.owner, X-mount.group, or X-mount.mode, especially when the bind source is below a user-writable ancestor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxAffected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-runtimeNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-sdkNot affected
Red Hat Enterprise Linux 9util-linuxNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesutil-linux-main-2.42.2-3.4.hum1FixedRHSA-2026:6316203.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2522684util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
15 дней назад

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

CVSS3: 7.8
nvd
15 дней назад

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

msrc
11 дней назад

Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection

CVSS3: 7.8
debian
15 дней назад

A flaw was found in util-linux. Restricted bind mounts take the source ...

7.8 High

CVSS3