OESA-2026-2211

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2211
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2211
Upstream
  • CVE-2026-27456
Published
2026-05-09T12:30:48Z
Modified
2026-05-09T12:46:32.713448Z
Summary
util-linux security update
Details

The util-linux package contains a random collection of files that implements some low-level basic linux utilities.

Security Fix(es):

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.(CVE-2026-27456)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
util-linux

Package

Name
util-linux
Purl
pkg:rpm/openEuler/util-linux&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.35.2-29.oe2003sp4

Ecosystem specific

{
    "src": [
        "util-linux-2.35.2-29.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "libblkid-2.35.2-29.oe2003sp4.aarch64.rpm",
        "libfdisk-2.35.2-29.oe2003sp4.aarch64.rpm",
        "libmount-2.35.2-29.oe2003sp4.aarch64.rpm",
        "libsmartcols-2.35.2-29.oe2003sp4.aarch64.rpm",
        "libuuid-2.35.2-29.oe2003sp4.aarch64.rpm",
        "python-libmount-2.35.2-29.oe2003sp4.aarch64.rpm",
        "util-linux-2.35.2-29.oe2003sp4.aarch64.rpm",
        "util-linux-debuginfo-2.35.2-29.oe2003sp4.aarch64.rpm",
        "util-linux-debugsource-2.35.2-29.oe2003sp4.aarch64.rpm",
        "util-linux-devel-2.35.2-29.oe2003sp4.aarch64.rpm",
        "util-linux-user-2.35.2-29.oe2003sp4.aarch64.rpm",
        "uuidd-2.35.2-29.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libblkid-2.35.2-29.oe2003sp4.x86_64.rpm",
        "libfdisk-2.35.2-29.oe2003sp4.x86_64.rpm",
        "libmount-2.35.2-29.oe2003sp4.x86_64.rpm",
        "libsmartcols-2.35.2-29.oe2003sp4.x86_64.rpm",
        "libuuid-2.35.2-29.oe2003sp4.x86_64.rpm",
        "python-libmount-2.35.2-29.oe2003sp4.x86_64.rpm",
        "util-linux-2.35.2-29.oe2003sp4.x86_64.rpm",
        "util-linux-debuginfo-2.35.2-29.oe2003sp4.x86_64.rpm",
        "util-linux-debugsource-2.35.2-29.oe2003sp4.x86_64.rpm",
        "util-linux-devel-2.35.2-29.oe2003sp4.x86_64.rpm",
        "util-linux-user-2.35.2-29.oe2003sp4.x86_64.rpm",
        "uuidd-2.35.2-29.oe2003sp4.x86_64.rpm"
    ],
    "noarch": [
        "util-linux-help-2.35.2-29.oe2003sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json"
openEuler:22.03-LTS-SP4
util-linux

Package

Name
util-linux
Purl
pkg:rpm/openEuler/util-linux&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.37.2-52.oe2203sp4

Ecosystem specific

{
    "src": [
        "util-linux-2.37.2-52.oe2203sp4.src.rpm"
    ],
    "aarch64": [
        "libblkid-2.37.2-52.oe2203sp4.aarch64.rpm",
        "libfdisk-2.37.2-52.oe2203sp4.aarch64.rpm",
        "libmount-2.37.2-52.oe2203sp4.aarch64.rpm",
        "libsmartcols-2.37.2-52.oe2203sp4.aarch64.rpm",
        "libuuid-2.37.2-52.oe2203sp4.aarch64.rpm",
        "python3-libmount-2.37.2-52.oe2203sp4.aarch64.rpm",
        "util-linux-2.37.2-52.oe2203sp4.aarch64.rpm",
        "util-linux-debuginfo-2.37.2-52.oe2203sp4.aarch64.rpm",
        "util-linux-debugsource-2.37.2-52.oe2203sp4.aarch64.rpm",
        "util-linux-devel-2.37.2-52.oe2203sp4.aarch64.rpm",
        "util-linux-user-2.37.2-52.oe2203sp4.aarch64.rpm",
        "uuidd-2.37.2-52.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libblkid-2.37.2-52.oe2203sp4.x86_64.rpm",
        "libfdisk-2.37.2-52.oe2203sp4.x86_64.rpm",
        "libmount-2.37.2-52.oe2203sp4.x86_64.rpm",
        "libsmartcols-2.37.2-52.oe2203sp4.x86_64.rpm",
        "libuuid-2.37.2-52.oe2203sp4.x86_64.rpm",
        "python3-libmount-2.37.2-52.oe2203sp4.x86_64.rpm",
        "util-linux-2.37.2-52.oe2203sp4.x86_64.rpm",
        "util-linux-debuginfo-2.37.2-52.oe2203sp4.x86_64.rpm",
        "util-linux-debugsource-2.37.2-52.oe2203sp4.x86_64.rpm",
        "util-linux-devel-2.37.2-52.oe2203sp4.x86_64.rpm",
        "util-linux-user-2.37.2-52.oe2203sp4.x86_64.rpm",
        "uuidd-2.37.2-52.oe2203sp4.x86_64.rpm"
    ],
    "noarch": [
        "util-linux-help-2.37.2-52.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json"
openEuler:24.03-LTS
util-linux

Package

Name
util-linux
Purl
pkg:rpm/openEuler/util-linux&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.39.1-38.oe2403sp3

Ecosystem specific

{
    "src": [
        "util-linux-2.39.1-38.oe2403.src.rpm",
        "util-linux-2.39.1-38.oe2403sp1.src.rpm",
        "util-linux-2.39.1-38.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libblkid-2.39.1-38.oe2403.aarch64.rpm",
        "libfdisk-2.39.1-38.oe2403.aarch64.rpm",
        "libmount-2.39.1-38.oe2403.aarch64.rpm",
        "libsmartcols-2.39.1-38.oe2403.aarch64.rpm",
        "libuuid-2.39.1-38.oe2403.aarch64.rpm",
        "python3-libmount-2.39.1-38.oe2403.aarch64.rpm",
        "util-linux-2.39.1-38.oe2403.aarch64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403.aarch64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403.aarch64.rpm",
        "util-linux-devel-2.39.1-38.oe2403.aarch64.rpm",
        "util-linux-user-2.39.1-38.oe2403.aarch64.rpm",
        "uuidd-2.39.1-38.oe2403.aarch64.rpm",
        "libblkid-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libfdisk-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libmount-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libuuid-2.39.1-38.oe2403sp1.aarch64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp1.aarch64.rpm",
        "uuidd-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libblkid-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libfdisk-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libmount-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libuuid-2.39.1-38.oe2403sp3.aarch64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp3.aarch64.rpm",
        "uuidd-2.39.1-38.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libblkid-2.39.1-38.oe2403.x86_64.rpm",
        "libfdisk-2.39.1-38.oe2403.x86_64.rpm",
        "libmount-2.39.1-38.oe2403.x86_64.rpm",
        "libsmartcols-2.39.1-38.oe2403.x86_64.rpm",
        "libuuid-2.39.1-38.oe2403.x86_64.rpm",
        "python3-libmount-2.39.1-38.oe2403.x86_64.rpm",
        "util-linux-2.39.1-38.oe2403.x86_64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403.x86_64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403.x86_64.rpm",
        "util-linux-devel-2.39.1-38.oe2403.x86_64.rpm",
        "util-linux-user-2.39.1-38.oe2403.x86_64.rpm",
        "uuidd-2.39.1-38.oe2403.x86_64.rpm",
        "libblkid-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libfdisk-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libmount-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libuuid-2.39.1-38.oe2403sp1.x86_64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp1.x86_64.rpm",
        "uuidd-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libblkid-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libfdisk-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libmount-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libuuid-2.39.1-38.oe2403sp3.x86_64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp3.x86_64.rpm",
        "uuidd-2.39.1-38.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "util-linux-help-2.39.1-38.oe2403.noarch.rpm",
        "util-linux-help-2.39.1-38.oe2403sp1.noarch.rpm",
        "util-linux-help-2.39.1-38.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json"
openEuler:24.03-LTS-SP1
util-linux

Package

Name
util-linux
Purl
pkg:rpm/openEuler/util-linux&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.39.1-38.oe2403sp1

Ecosystem specific

{
    "src": [
        "util-linux-2.39.1-38.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "libblkid-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libfdisk-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libmount-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp1.aarch64.rpm",
        "libuuid-2.39.1-38.oe2403sp1.aarch64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp1.aarch64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp1.aarch64.rpm",
        "uuidd-2.39.1-38.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "libblkid-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libfdisk-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libmount-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp1.x86_64.rpm",
        "libuuid-2.39.1-38.oe2403sp1.x86_64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp1.x86_64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp1.x86_64.rpm",
        "uuidd-2.39.1-38.oe2403sp1.x86_64.rpm"
    ],
    "noarch": [
        "util-linux-help-2.39.1-38.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json"
openEuler:24.03-LTS-SP3
util-linux

Package

Name
util-linux
Purl
pkg:rpm/openEuler/util-linux&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.39.1-38.oe2403sp3

Ecosystem specific

{
    "src": [
        "util-linux-2.39.1-38.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libblkid-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libfdisk-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libmount-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp3.aarch64.rpm",
        "libuuid-2.39.1-38.oe2403sp3.aarch64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp3.aarch64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp3.aarch64.rpm",
        "uuidd-2.39.1-38.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libblkid-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libfdisk-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libmount-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libsmartcols-2.39.1-38.oe2403sp3.x86_64.rpm",
        "libuuid-2.39.1-38.oe2403sp3.x86_64.rpm",
        "python3-libmount-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-debuginfo-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-debugsource-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-devel-2.39.1-38.oe2403sp3.x86_64.rpm",
        "util-linux-user-2.39.1-38.oe2403sp3.x86_64.rpm",
        "uuidd-2.39.1-38.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "util-linux-help-2.39.1-38.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2211.json"