CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8702-1: util-linux vulnerabilities

unknownCVE-2026-13595CVE-2026-27456CVE-2026-3184CVE-2026-53612CVE-2026-53613CVE-2026-53614
It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present a crafted block device image could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-13595) It was discovered that the mount utility in util-linux had a time-of-check- time-of-use vulnerability when setting up loop devices. A local attacker could possibly use this issue to obtain unauthorized read access to root- protected files and block devices. (CVE-2026-27456) It was discovered that the login utility in util-linux improperly canonicalized hostnames when invoked with the -h option. A remote attacker could possibly use this issue to bypass host-based access control rules. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-3184) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability in its ownership hook. A local attacker could possibly use this issue to gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53612) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability that allowed target path redirection during mount operations. A local attacker could possibly use this issue to gain elevated privileges. (CVE-2026-53613) It was discovered that libmount in util-linux improperly handled the LIBMOUNT_FORCE_MOUNT2 environment variable in the SUID mount utility. A local attacker could possibly use this issue to bypass nosuid and noexec mount options and gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53614) It was discovered that libblkid in util-linux had an integer overflow vulnerability when parsing DOS partition tables. An attacker who could present a crafted block device image could possibly use this issue to cause a denial of service. (CVE-2026-53615)

CSIRTS triage

What
util-linux contains heap use-after-free in libblkid, time-of-check-time-of-use in mount and login utilities, and other privilege escalation issues.
Who is affected
Local users with access to block devices or login functionality on systems running util-linux.
Urgency
High urgency; local privilege escalation and information disclosure affecting mount and login components.
Action
Apply security updates from USN-8702-1 covering all affected utilities and versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch util-linux

Get an email when a new util-linux advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-31
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8702-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-13595coverage & exploitation statusNVD · CVE.org
CVE-2026-27456coverage & exploitation statusNVD · CVE.org
CVE-2026-3184coverage & exploitation statusNVD · CVE.org
CVE-2026-53612coverage & exploitation statusNVD · CVE.org
CVE-2026-53613coverage & exploitation statusNVD · CVE.org
CVE-2026-53614coverage & exploitation statusNVD · CVE.org
CVE-2026-53615coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices