ECHO-3eb2-a6d4-7b02

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-3eb2-a6d4-7b02.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-3eb2-a6d4-7b02
Upstream
  • CVE-2026-78409
Withdrawn
2026-09-06T09:15:09.413Z
Published
2026-09-03T09:59:27.172Z
Modified
2026-09-06T09:45:03.221299622Z
Summary
The detached-tree X-mount.subdir path arrived in 2.42 (ae19f7546); our libmount has no AT_SYMLINK_NOFOLLOW, no api->subdir in hook_mount.c and no 6.15 logic. Upstream shipped 2.41.6 the same day as 2.42.3 with the other three CVEs and deliberately not this one. Debian marks trixie vulnerable but also bookworm 2.38.1, which predates the path entirely. https://security-tracker.debian.org/tracker/CVE-2026-78409
Details
References

Affected packages

Echo / util-linux

Package

Name
util-linux
Purl
pkg:deb/echo/util-linux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.41.5-0+deb13u1+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-3eb2-a6d4-7b02.json"