Opened 6 hours ago
Last modified 5 hours ago
#6014 new enhancement
util-linux-2.42.3
| Reported by: | Bruce Dubbs | Owned by: | lfs-book |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.2 |
| Component: | Book | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New point version.
util-linux 2.42.3 Release Notes
Security fixes:
CVE-2026-76642 - mount(8) post-mount hooks execute after helper failure.
When an external mount.<type> helper exits nonzero, post-mount hooks (X-mount.idmap, X-mount.owner/group/mode) still execute as if the mount had succeeded, allowing privileged operations on the pre-existing target filesystem.
CVE-2026-78410 - mount(8) TOCTOU race on source path.
In restricted (SUID, non-root) mode, the source path is canonicalized with realpath() as euid=0, following symlinks through user-writable directories. Additionally, open_tree() follows symlinks in intermediate path components. A local attacker can redirect a privileged mount or post-mount ownership change to an arbitrary path.
CVE-2026-78409 - mount(8) X-mount.subdir symlink escape.
The open_tree() call used to open a subdirectory on a detached mount follows symlinks in intermediate path components, allowing escape from the detached tree.
CVE-2026-78408 - nsenter(1), unshare(1) file descriptor leak.
File descriptors in nsenter and unshare were not created with O_CLOEXEC, potentially leaking them across exec. Added O_CLOEXEC as defense in depth.
wall(1), write(1) - hostname escape sequence injection.
The CVE-2024-28085 fix sanitized only message bodies; the banner headers still interpolated the system hostname without sanitization. An unprivileged user can inject terminal escape sequences via a user namespace hostname. Additional fix for CVE-2024-28085. Reported-by: Skyler Ferrante
Change History (2)
comment:1 by , 6 hours ago
| Summary: | util-linux-2.42,3 → util-linux-2.42.3 |
|---|

This probably needs a sed (adapted from upstream):
sed -i '/namespace.h/i #include "fileutils.h"' libmount/src/hook_idmap.c