ZeroHour
Product

util-linux 2.42.3

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Vulnerability fixes in util-linux-2.42.3

util-linux 2.42.3 patches mount(8) flaws CVE-2026-76642 and CVE-2026-78410, which allow privileged operations after mount helper failure.

util-linux 2.42.3 ships security fixes for two mount(8) vulnerabilities. CVE-2026-76642 causes post-mount hooks (X-mount.idmap, X-mount.owner/group/mode) to run even when an external mount helper exits nonzero, permitting privileged operations on the pre-existing target filesystem. CVE-2026-78410 is a time-of-check-to-time-of-use (TOCTOU) issue in mount(8). No exploitation or PoC is mentioned in the release notes.

Related CVEs

  • Missing Exit-Status Check in util-linux Mount Helpers Enables Local Privilege Escalation
    util-linux versions through 2.41.5 and through 2.42.2 fail to check the exit status of mount helpers before running post-mount hooks, so privileged post-mount actions still execute after a helper has failed. A local unprivileged user who can trigger affected mount paths (for example fstab-based mounts using the X-mount.idmap or X-mount.owner hooks) can induce a helper failure and have the hooks clone filesystems with inherited suid bits or modify target inode permissions. Successful exploitation yields local privilege escalation, letting the attacker perform privileged operations on pre-existing filesystems. Any Linux deployment running an affected util-linux version is potentially affected, though exploitability depends on local configurations that allow unprivileged users to invoke these mount helpers rather than on network exposure. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
    · util-linux project (upstream; shipped by Linux distributions) util-linux through 2.41.5 and through 2.42.2 (fixed in 2.42.3)mass
  • TOCTOU race in util-linux mount(8) lets local users redirect restricted bind mounts
    A time-of-check to time-of-use (TOCTOU) race (CWE-367) exists in util-linux's mount(8): restricted bind mounts take their source path from fstab but do not pin that source before performing the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor directory can race the SUID mount helper, causing it to bind a different host directory than the one authorized in fstab. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then applies the ownership or mode change to the redirected inode, letting the attacker have root alter arbitrary host directories, with potential for privilege escalation (CVSS 3.1: 7.8 high, local vector). Any Linux system running an affected util-linux that exposes user-mountable fstab bind entries is affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known; EPSS estimates only a 0.1% probability of exploitation within 30 days.
    · util-linux project (CNA: Red Hat) util-linux (mount(8)) versions prior to 2.42.3 (fixes included in util-linux 2.42.3)

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.