CVE-2026-78410
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
Schwachstellenklasse
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
Quellen
- https://access.redhat.com/errata/RHSA-2026:63162
- https://access.redhat.com/security/cve/CVE-2026-78410
- https://bugzilla.redhat.com/show_bug.cgi?id=2522684
- https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m
- https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.