USN-8702-1: util-linux vulnerabilities
It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present a crafted block device image could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-13595) It was discovered that the mount utility in util-linux had a time-of-check- time-of-use vulnerability when setting up loop devices. A local attacker could possibly use this issue to obtain unauthorized read access to root- protected files and block devices. (CVE-2026-27456) It was discovered that the login utility in util-linux improperly canonicalized hostnames when invoked with the -h option. A remote attacker could possibly use this issue to bypass host-based access control rules. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-3184) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability in its ownership hook. A local attacker could possibly use this issue to gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53612) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability that allowed target path redirection during mount operations. A local attacker could possibly use this issue to gain elevated privileges. (CVE-2026-53613) It was discovered that libmount in util-linux improperly handled the LIBMOUNT_FORCE_MOUNT2 environment variable in the SUID mount utility. A local attacker could possibly use this issue to bypass nosuid and noexec mount options and gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53614) It was discovered that libblkid in util-linux had an integer overflow vulnerability when parsing DOS partition tables. An attacker who could present a crafted block device image could possibly use this issue to cause a denial of service. (CVE-2026-53615)
CSIRTS triage
- What
- util-linux contains heap use-after-free in libblkid, time-of-check-time-of-use in mount and login utilities, and other privilege escalation issues.
- Who is affected
- Local users with access to block devices or login functionality on systems running util-linux.
- Urgency
- High urgency; local privilege escalation and information disclosure affecting mount and login components.
- Action
- Apply security updates from USN-8702-1 covering all affected utilities and versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch util-linux
Get an email when a new util-linux advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8702-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-135950.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-274560.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-31840.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13595 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27456 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3184 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53612 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53613 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53614 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53615 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- low[UPDATE] [low] util-linux: Vulnerability enables bypass of security measurescert-bund
- medium[UPDATE] [medium] util-linux: Vulnerability enables denial of service and information disclosurecert-bund
- high[NEW] [high] util-linux: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Debian Linux kernel (August 21, 2026)cert-fr-avis
- unknownDSA-6442-1 util-linux - security updatedebian
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 7, 2026)cert-fr-avis
- mediumCVE-2026-13595: A flaw was found in the libblkid library of util-linux. During nested partition probing, the B…nvd
- mediumCVE-2026-13595: Util-linux: util-linux: heap use-after-free in libblkid nested partition probingmsrc
More from Ubuntu Security Notices
- unknownUSN-8737-1: GNU C Library vulnerabilities2026-09-08
- unknownUSN-8736-1: Perl vulnerabilities2026-09-08
- unknownUSN-8735-1: HSQLDB vulnerability2026-09-08
- unknownUSN-8734-1: PHP vulnerabilities2026-09-07
- unknownUSN-8733-1: Gzip vulnerabilities2026-09-07