It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present a crafted block device image could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-13595)
It was discovered that the mount utility in util-linux had a time-of-check- time-of-use vulnerability when setting up loop devices. A local attacker could possibly use this issue to obtain unauthorized read access to root- protected files and block devices. (CVE-2026-27456)
It was discovered that the login utility in util-linux improperly canonicalized hostnames when invoked with the -h option. A remote attacker could possibly use this issue to bypass host-based access control rules. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-3184)
It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability in its ownership hook. A local attacker could possibly use this issue to gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53612)
It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability that allowed target path redirection during mount operations. A local attacker could possibly use this issue to gain elevated privileges. (CVE-2026-53613)
It was discovered that libmount in util-linux improperly handled the LIBMOUNTFORCEMOUNT2 environment variable in the SUID mount utility. A local attacker could possibly use this issue to bypass nosuid and noexec mount options and gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53614)
It was discovered that libblkid in util-linux had an integer overflow vulnerability when parsing DOS partition tables. An attacker who could present a crafted block device image could possibly use this issue to cause a denial of service. (CVE-2026-53615)
{
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.37.2-4ubuntu3.6"
},
{
"binary_name": "eject",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "fdisk",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "libblkid1",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "libmount1",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "libuuid1",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "mount",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "rfkill",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "util-linux",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.37.2-4ubuntu3.6"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.37.2-4ubuntu3.6"
}
],
"availability": "No subscription required"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8702-1.json"
{
"cves": [
{
"id": "CVE-2026-13595",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-27456",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53613",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53615",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
{
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.39.3-9ubuntu6.6"
},
{
"binary_name": "eject",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "fdisk",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libblkid1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libmount1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "libuuid1",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "mount",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "rfkill",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.39.3-9ubuntu6.6"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.39.3-9ubuntu6.6"
}
],
"availability": "No subscription required"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8702-1.json"
{
"cves": [
{
"id": "CVE-2026-13595",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-27456",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53612",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53613",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53614",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53615",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
{
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.41.3-3ubuntu2.2"
},
{
"binary_name": "eject",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "fdisk",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "lastlog2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libblkid1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "liblastlog2-2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libmount1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libpam-lastlog2",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "libuuid1",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "login",
"binary_version": "1:4.16.0-2+really2.41.3-3ubuntu2.2"
},
{
"binary_name": "mount",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "rfkill",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.41.3-3ubuntu2.2"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.41.3-3ubuntu2.2"
}
],
"availability": "No subscription required"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8702-1.json"
{
"cves": [
{
"id": "CVE-2026-3184",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-13595",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-27456",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53612",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53613",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53614",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2026-53615",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}