Ubuntu alert USN-8702-1 (util-linux)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8702-1] util-linux vulnerabilities | |
| Date: | Mon, 31 Aug 2026 14:09:54 +0000 | |
| Message-ID: | <E1x12hu-0004oa-9U@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8702-1 August 31, 2026 util-linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in util-linux. Software Description: - util-linux: miscellaneous system utilities Details: It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present a crafted block device image could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-13595) It was discovered that the mount utility in util-linux had a time-of-check- time-of-use vulnerability when setting up loop devices. A local attacker could possibly use this issue to obtain unauthorized read access to root- protected files and block devices. (CVE-2026-27456) It was discovered that the login utility in util-linux improperly canonicalized hostnames when invoked with the -h option. A remote attacker could possibly use this issue to bypass host-based access control rules. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-3184) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability in its ownership hook. A local attacker could possibly use this issue to gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53612) It was discovered that libmount in util-linux had a time-of-check-time-of- use vulnerability that allowed target path redirection during mount operations. A local attacker could possibly use this issue to gain elevated privileges. (CVE-2026-53613) It was discovered that libmount in util-linux improperly handled the LIBMOUNT_FORCE_MOUNT2 environment variable in the SUID mount utility. A local attacker could possibly use this issue to bypass nosuid and noexec mount options and gain elevated privileges. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53614) It was discovered that libblkid in util-linux had an integer overflow vulnerability when parsing DOS partition tables. An attacker who could present a crafted block device image could possibly use this issue to cause a denial of service. (CVE-2026-53615) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS util-linux 2.41.3-3ubuntu2.2 Ubuntu 24.04 LTS util-linux 2.39.3-9ubuntu6.6 Ubuntu 22.04 LTS util-linux 2.37.2-4ubuntu3.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8702-1 CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-53615 Package Information: https://launchpad.net/ubuntu/+source/util-linux/2.41.3-3u... https://launchpad.net/ubuntu/+source/util-linux/2.39.3-9u... https://launchpad.net/ubuntu/+source/util-linux/2.37.2-4u...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqVh3cACgkQcpJm3tlz hgEIpA//R8NG2TRBoi142PjscNdYUo8gdmEIhMCA1X8TKgjneiW24GXy67kxMzVp P/iHVAWE0yTsWKqwGHK0SGdqFulmfcZ1S/Rmzxv2vGlCvAOecloAqjeIHhVVHFf2 c4epaeB0ivRDGOK0eRGaYAv3C+wPdulfqHbBenvqofgiT8+PFn/7iKyJLCZG/NEO 3ZFWdIj7jMX7SjC2NejG/L+rFaJQFIlDKfxSOxLAdBCSs78E5/3XRTWC9urpvZ1x 1zKXl/7tmSeSEPBmgw6lztprVURVvlnd1zdy5NxGJpMz7t/Tz1E/60d7AoSPtWtL pa46sUKUz8JVSdQ9qFdfjAhDVfx37ld9ZQQ9iE1HOclgJtaFoOtfUzHGZ22dzMp9 /DYrN8+QQG21fbjpM4jQDdJY8EYjCYCIJXWI/TRqUyTuxIR+dOY7fb5mNODFWLI/ dQeliXV0NPq3OOwsumUzXgaplEzpysYXtsDKD/bxBrGVeqbfxs7Oxj9jiqvJjK3p G5S2TdKmZKxnLU2aIEQ+YyatHLQWoFfMNhb1SwNLMOKp1WOViWn1B234epqhtvaQ VZkjxvkPIEKOUE0DKC2dIbAft8zaElZr9C9uH896u0LBMKTWCtw1e0s8KayPuuO5 12OiOa3zLZgiu1jDs2vAD8YpNxNLLQm0rCV/Bp0kFL23xhduc/c= =v1KQ -----END PGP SIGNATURE-----
