Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20495-1

Опубликовано: 09 апр. 2026
Источник: suse-cvrf

Описание

Security update for util-linux

This update for util-linux fixes the following issues:

Security issues:

  • CVE-2025-14104: heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666).
  • CVE-2026-3184: access control bypass due to improper hostname canonicalization in login (bsc#1258859).

Non security issues:

  • fdisk: Fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465).
  • lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682).

Список пакетов

openSUSE Leap 16.0
lastlog2-2.41.1-160000.3.1
libblkid-devel-2.41.1-160000.3.1
libblkid-devel-static-2.41.1-160000.3.1
libblkid1-2.41.1-160000.3.1
libfdisk-devel-2.41.1-160000.3.1
libfdisk-devel-static-2.41.1-160000.3.1
libfdisk1-2.41.1-160000.3.1
liblastlog2-2-2.41.1-160000.3.1
liblastlog2-devel-2.41.1-160000.3.1
libmount-devel-2.41.1-160000.3.1
libmount-devel-static-2.41.1-160000.3.1
libmount1-2.41.1-160000.3.1
libsmartcols-devel-2.41.1-160000.3.1
libsmartcols-devel-static-2.41.1-160000.3.1
libsmartcols1-2.41.1-160000.3.1
libuuid-devel-2.41.1-160000.3.1
libuuid-devel-static-2.41.1-160000.3.1
libuuid1-2.41.1-160000.3.1
python313-libmount-2.41.1-160000.3.1
util-linux-2.41.1-160000.3.1
util-linux-extra-2.41.1-160000.3.1
util-linux-lang-2.41.1-160000.3.1
util-linux-systemd-2.41.1-160000.3.1
util-linux-tty-tools-2.41.1-160000.3.1
uuidd-2.41.1-160000.3.1

Описание

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.


Затронутые продукты
openSUSE Leap 16.0:lastlog2-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid-devel-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid-devel-static-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid1-2.41.1-160000.3.1

Ссылки

Описание

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.


Затронутые продукты
openSUSE Leap 16.0:lastlog2-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid-devel-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid-devel-static-2.41.1-160000.3.1
openSUSE Leap 16.0:libblkid1-2.41.1-160000.3.1

Ссылки