CVE-2026-78410

Published: September 5, 2026Last modified: September 15, 2026

Description

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSutil-linuxUnknown (2.38.1-r2)
25 LTSutil-linuxUnknown (2.41-r6)
Streamutil-linuxFixed (2.42.3-r1)
Hardened Containers23 LTSutil-linuxUnknown (2.38.1-r2)
25 LTSutil-linuxUnknown (2.41-r6)
Streamutil-linuxFixed (2.42.3-r1)

References

ON THIS PAGE