openSUSE-SU-2026:21905-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21905-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21905-1
Upstream
CVE (8)
Related
Published
2026-09-22T07:23:43Z
Modified
2026-09-25T18:23:12Z
Summary
Security update for util-linux
Details

This update for util-linux fixes the following issues:

  • CVE-2026-13595: heap use-after-free in libblkid nested partition probing (bsc#1269583).
  • CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
  • CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
  • CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
  • CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886).
  • CVE-2026-76642: failed external mount helper triggers privileged X-mount post-hooks, which enables local privilege escalation (bsc#1278349).
  • CVE-2026-78408: nsenter --join-cgroup leaks root cgroup migration authority, which allows for migration or termination of root processes (bsc#1278348).
  • CVE-2026-78410: restricted bind mounts do not pin the source, which allows for X-mount.owner/group/mode redirection (bsc#1278347).

Changes for util-linux:

  • lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
  • lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
  • lib/fileutils: fix unused parameter warnings without SYS_openat2
  • libmount: add missing fileutils.h include to hook_idmap.c
  • libmount: add mnt_open_tree() helper for safe tree opening
  • libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410)
  • libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410)
  • libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642)
  • libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
  • nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
  • nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408)
  • wall, write: sanitize hostname in banner header (bsc#1275441)
  • Add missing function. (bsc#1275441)
  • ipcutils: Prevent using uninitialized variable (bsc#1268886)
  • BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them.
  • INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons.
  • liblastlog2: Wait on busy SQLite connections (bsc#1268886).
  • libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886).
  • libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595)
  • libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
  • fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886).
  • libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
  • libmount: ignore X-mount.nocanonicalize for restricted users
  • libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
  • libmount: restrict X-mount.subdir for non-root (bsc#1268886).
  • libmount: use fd_target in hook_idmap for move_mount()
  • libmount: add mount ID verification and man page TOCTOU note
  • loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606).
  • Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219).
References

Affected packages

openSUSE:Leap 16.0 / python-libmount

Package

Name
python-libmount
Purl
pkg:rpm/opensuse/python-libmount&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.41.1-160000.5.1

Ecosystem specific

{
    "binaries":  [
        {
            "lastlog2":  "2.41.1-160000.5.1",
            "libblkid-devel":  "2.41.1-160000.5.1",
            "libblkid-devel-static":  "2.41.1-160000.5.1",
            "libblkid1":  "2.41.1-160000.5.1",
            "libfdisk-devel":  "2.41.1-160000.5.1",
            "libfdisk-devel-static":  "2.41.1-160000.5.1",
            "libfdisk1":  "2.41.1-160000.5.1",
            "liblastlog2-2":  "2.41.1-160000.5.1",
            "liblastlog2-devel":  "2.41.1-160000.5.1",
            "libmount-devel":  "2.41.1-160000.5.1",
            "libmount-devel-static":  "2.41.1-160000.5.1",
            "libmount1":  "2.41.1-160000.5.1",
            "libsmartcols-devel":  "2.41.1-160000.5.1",
            "libsmartcols-devel-static":  "2.41.1-160000.5.1",
            "libsmartcols1":  "2.41.1-160000.5.1",
            "libuuid-devel":  "2.41.1-160000.5.1",
            "libuuid-devel-static":  "2.41.1-160000.5.1",
            "libuuid1":  "2.41.1-160000.5.1",
            "python313-libmount":  "2.41.1-160000.5.1",
            "util-linux":  "2.41.1-160000.5.1",
            "util-linux-extra":  "2.41.1-160000.5.1",
            "util-linux-lang":  "2.41.1-160000.5.1",
            "util-linux-systemd":  "2.41.1-160000.5.1",
            "util-linux-tty-tools":  "2.41.1-160000.5.1",
            "uuidd":  "2.41.1-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21905-1.json"

openSUSE:Leap 16.0 / util-linux

Package

Name
util-linux
Purl
pkg:rpm/opensuse/util-linux&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.41.1-160000.5.1

Ecosystem specific

{
    "binaries":  [
        {
            "lastlog2":  "2.41.1-160000.5.1",
            "libblkid-devel":  "2.41.1-160000.5.1",
            "libblkid-devel-static":  "2.41.1-160000.5.1",
            "libblkid1":  "2.41.1-160000.5.1",
            "libfdisk-devel":  "2.41.1-160000.5.1",
            "libfdisk-devel-static":  "2.41.1-160000.5.1",
            "libfdisk1":  "2.41.1-160000.5.1",
            "liblastlog2-2":  "2.41.1-160000.5.1",
            "liblastlog2-devel":  "2.41.1-160000.5.1",
            "libmount-devel":  "2.41.1-160000.5.1",
            "libmount-devel-static":  "2.41.1-160000.5.1",
            "libmount1":  "2.41.1-160000.5.1",
            "libsmartcols-devel":  "2.41.1-160000.5.1",
            "libsmartcols-devel-static":  "2.41.1-160000.5.1",
            "libsmartcols1":  "2.41.1-160000.5.1",
            "libuuid-devel":  "2.41.1-160000.5.1",
            "libuuid-devel-static":  "2.41.1-160000.5.1",
            "libuuid1":  "2.41.1-160000.5.1",
            "python313-libmount":  "2.41.1-160000.5.1",
            "util-linux":  "2.41.1-160000.5.1",
            "util-linux-extra":  "2.41.1-160000.5.1",
            "util-linux-lang":  "2.41.1-160000.5.1",
            "util-linux-systemd":  "2.41.1-160000.5.1",
            "util-linux-tty-tools":  "2.41.1-160000.5.1",
            "uuidd":  "2.41.1-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21905-1.json"

openSUSE:Leap 16.0 / util-linux-systemd

Package

Name
util-linux-systemd
Purl
pkg:rpm/opensuse/util-linux-systemd&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.41.1-160000.5.1

Ecosystem specific

{
    "binaries":  [
        {
            "lastlog2":  "2.41.1-160000.5.1",
            "libblkid-devel":  "2.41.1-160000.5.1",
            "libblkid-devel-static":  "2.41.1-160000.5.1",
            "libblkid1":  "2.41.1-160000.5.1",
            "libfdisk-devel":  "2.41.1-160000.5.1",
            "libfdisk-devel-static":  "2.41.1-160000.5.1",
            "libfdisk1":  "2.41.1-160000.5.1",
            "liblastlog2-2":  "2.41.1-160000.5.1",
            "liblastlog2-devel":  "2.41.1-160000.5.1",
            "libmount-devel":  "2.41.1-160000.5.1",
            "libmount-devel-static":  "2.41.1-160000.5.1",
            "libmount1":  "2.41.1-160000.5.1",
            "libsmartcols-devel":  "2.41.1-160000.5.1",
            "libsmartcols-devel-static":  "2.41.1-160000.5.1",
            "libsmartcols1":  "2.41.1-160000.5.1",
            "libuuid-devel":  "2.41.1-160000.5.1",
            "libuuid-devel-static":  "2.41.1-160000.5.1",
            "libuuid1":  "2.41.1-160000.5.1",
            "python313-libmount":  "2.41.1-160000.5.1",
            "util-linux":  "2.41.1-160000.5.1",
            "util-linux-extra":  "2.41.1-160000.5.1",
            "util-linux-lang":  "2.41.1-160000.5.1",
            "util-linux-systemd":  "2.41.1-160000.5.1",
            "util-linux-tty-tools":  "2.41.1-160000.5.1",
            "uuidd":  "2.41.1-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21905-1.json"