Util-linux Security Update Advisory

Util-linux Security Update Advisory
  • A security update has been released to address a vulnerability in Ubuntu’s util-linux.
  • The affected products are util-linux in Ubuntu 26.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 22.04 LTS.
  • The vulnerabilities addressed are as follows:
    • CVE-2026-13595, a use-after-free vulnerability occurring during nested partition traversal in libblkid within util-linux.
    • CVE-2026-27456, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability occurring during the Loop Device configuration process in the mount utility of util-linux.
    • CVE-2026-3184, an access control bypass vulnerability in the login utility of util-linux caused by insufficient hostname normalization.
    • CVE-2026-53612, a privilege escalation vulnerability caused by a TOCTOU in the ownership hook handling process of util-linux’s libmount.
    • CVE-2026-53613: A TOCTOU-based privilege escalation vulnerability in util-linux’s libmount caused by the ability to modify the mount target path.
    • CVE-2026-53614: A privilege escalation vulnerability in the SUID mount utility of util-linux caused by improper handling of the LIBMOUNTFORCEMOUNT2 environment variable.
    • CVE-2026-53615: A denial-of-service (DoS) vulnerability in util-linux’s libblkid caused by an integer overflow during DOS partition table processing.
  • The versions requiring updates are as follows:
    • CVE-2026-13595, CVE-2026-27456, CVE-2026-53613, CVE-2026-53615 affects Ubuntu 26.04 LTS with util-linux versions below 2.41.3-3Ubuntu2.2, Ubuntu 24.04 LTS with util-linux versions below 2.39.3-9Ubuntu6.6, Versions of util-linux prior to 2.37.2-4Ubuntu3.6 On Ubuntu 22.04 LTS.
    • CVE-2026-3184 affects versions of util-linux prior to 2.41.3-3Ubuntu2.2 On Ubuntu 26.04 LTS.
    • CVE-2026-53612 and CVE-2026-53614 affect util-linux versions earlier than 2.41.3-3Ubuntu2.2 Or lower in Ubuntu 26.04 LTS and util-linux versions lower than 2.39.3-9Ubuntu6.6 In Ubuntu 24.04 LTS.
  • Vulnerability Patches have been released via the latest updates, and users should update to the relevant versions.
  • The reference site is USN-8702-1: util-linux vulnerabilities.