{"id":"SUSE-SU-2026:23870-1","summary":"Security update for util-linux","details":"This update for util-linux fixes the following issues:\n\n- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).\n- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).\n- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).\n- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).\n- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec\n  Bypass in SUID mount(8) (bsc#1268886).\n- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege\n  escalation (bsc#1278349).\n- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or\n  termination of root processes (bsc#1278348).\n- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`\n  redirection (bsc#1278347).\n\nChanges for util-linux:\n\n- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)\n- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value\n- lib/fileutils: fix unused parameter warnings without SYS_openat2\n- libmount: add missing fileutils.h include to hook_idmap.c\n- libmount: add mnt_open_tree() helper for safe tree opening\n- libmount: pin source path with openat2() for restricted users\n (bsc#1275441, bsc#1278347, CVE-2026-78410)\n- libmount: restrict source path canonicalization for non-root\n users (bsc#1275441, bsc#1278347, CVE-2026-78410)\n- libmount: skip post-mount hooks after failed mount helper\n (bsc#1275441, bsc#1278349, CVE-2026-76642)\n- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook\n- nsenter: close cgroup.procs fd after join to prevent authority\n leak (bsc#1275441, bsc#1278348, CVE-2026-78408)\n- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,\n bsc#1278348, CVE-2026-78408)\n- wall, write: sanitize hostname in banner header (bsc#1275441)\n- Add missing function. (bsc#1275441)\n- ipcutils: Prevent using uninitialized variable (bsc#1268886)\n- BREAKING CHANGE:\n Paths must always be canonicalized for unprivileged users to\n ensure safe target resolution. X-mount.nocanonicalize is ignored\n for them.\n- INCOMAPTIBLE CHANGE (linux \u003c 6.15):\n X-mount.subdir: The safe detached subdirectory is no more\n supported for unprivileged users for safety reasons.\n- liblastlog2: Wait on busy SQLite connections (bsc#1268886).\n- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root\n (bsc#1268886).\n- libblkid: Fix use-after-free in nested partition probing\n (bsc#1269583, bsc#1268886, CVE-2026-13595)\n- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy\n mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).\n- fileutils: add ul_open_no_symlinks() needed by other patches\n (bsc#1268886).\n- libmount: add fd_target to context for TOCTOU race condition\n prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).\n- libmount: ignore X-mount.nocanonicalize for restricted users\n- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,\n CVE-2026-53612, GHSA-g8wm-75wr-g2vh).\n- libmount: restrict X-mount.subdir for non-root (bsc#1268886).\n- libmount: use fd_target in hook_idmap for move_mount()\n- libmount: add mount ID verification and man page TOCTOU note\n- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file\n (bsc#1268886#c2, bsc#1261606).\n- Ignore pam-config error that prevents update failure if common*\n pam configuration is not symlink to common-*-pc (bsc#1270219).\n","modified":"2026-09-27T18:23:17.189268803Z","published":"2026-09-22T07:23:33Z","related":["CVE-2026-13595","CVE-2026-27456","CVE-2026-53612","CVE-2026-53613","CVE-2026-53614","CVE-2026-76642","CVE-2026-78408","CVE-2026-78410"],"upstream":["CVE-2026-13595","CVE-2026-27456","CVE-2026-53612","CVE-2026-53613","CVE-2026-53614","CVE-2026-76642","CVE-2026-78408","CVE-2026-78410"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623870-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270219"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278347"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278348"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53612"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53613"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76642"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78410"}],"affected":[{"package":{"name":"python-libmount","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/python-libmount&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"util-linux-systemd":"2.41.1-160000.5.1","libblkid1":"2.41.1-160000.5.1","util-linux":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1","util-linux-lang":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","libsmartcols1":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","libuuid-devel-static":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}},{"package":{"name":"util-linux","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/util-linux&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"libuuid-devel-static":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","util-linux-systemd":"2.41.1-160000.5.1","libblkid1":"2.41.1-160000.5.1","util-linux-lang":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","libsmartcols1":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","util-linux":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}},{"package":{"name":"util-linux-systemd","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"libblkid1":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","util-linux-lang":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1","libuuid-devel-static":"2.41.1-160000.5.1","util-linux-systemd":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","libsmartcols1":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","util-linux":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}},{"package":{"name":"python-libmount","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/python-libmount&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"util-linux-lang":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","libsmartcols1":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","libuuid-devel-static":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","libblkid1":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1","util-linux":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","util-linux-systemd":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}},{"package":{"name":"util-linux","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/util-linux&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"util-linux":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1","util-linux-systemd":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1","libuuid-devel-static":"2.41.1-160000.5.1","util-linux-lang":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","libblkid1":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","libsmartcols1":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}},{"package":{"name":"util-linux-systemd","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.1-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"libsmartcols1":"2.41.1-160000.5.1","libfdisk-devel-static":"2.41.1-160000.5.1","libsmartcols-devel":"2.41.1-160000.5.1","libmount-devel":"2.41.1-160000.5.1","libblkid-devel":"2.41.1-160000.5.1","libmount-devel-static":"2.41.1-160000.5.1","util-linux-systemd":"2.41.1-160000.5.1","libfdisk-devel":"2.41.1-160000.5.1","libblkid1":"2.41.1-160000.5.1","liblastlog2-2":"2.41.1-160000.5.1","libfdisk1":"2.41.1-160000.5.1","libuuid1":"2.41.1-160000.5.1","libsmartcols-devel-static":"2.41.1-160000.5.1","util-linux-tty-tools":"2.41.1-160000.5.1","libmount1":"2.41.1-160000.5.1","python313-libmount":"2.41.1-160000.5.1","libblkid-devel-static":"2.41.1-160000.5.1","libuuid-devel-static":"2.41.1-160000.5.1","liblastlog2-devel":"2.41.1-160000.5.1","uuidd":"2.41.1-160000.5.1","util-linux-lang":"2.41.1-160000.5.1","util-linux":"2.41.1-160000.5.1","libuuid-devel":"2.41.1-160000.5.1","lastlog2":"2.41.1-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23870-1.json"}}],"schema_version":"1.9.0"}