7.0 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
11 packages
- more
- wall
- eject
- mount
- logger
- umount
- hexdump
- libuuid
- utillinux
- util-linux
- libsmartcols
- @LeSuisse restored package util-linux
-
@LeSuisse
ignored
18 packages
- unixtools.col
- unixtools.fsck
- unixtools.more
- unixtools.wall
- unixtools.eject
- unixtools.fdisk
- unixtools.mount
- unixtools.write
- unixtools.column
- unixtools.getopt
- unixtools.logger
- unixtools.script
- unixtools.umount
- unixtools.hexdump
- unixtools.whereis
- util-linuxMinimal
- uutils-util-linux
- unixtools.util-linux
- @LeSuisse accepted
- @LeSuisse published on GitHub
Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
References
Affected products
Matching in nixpkgs
Ignored packages (28)
pkgs.more
None
pkgs.wall
None
pkgs.eject
None
pkgs.mount
None
pkgs.logger
None
pkgs.umount
None
pkgs.hexdump
None
pkgs.libuuid
Set of system utilities for Linux
pkgs.utillinux
Set of system utilities for Linux
pkgs.libsmartcols
Set of system utilities for Linux
pkgs.unixtools.col
None
pkgs.unixtools.fsck
None
pkgs.unixtools.more
None
pkgs.unixtools.wall
None
pkgs.unixtools.eject
None
pkgs.unixtools.fdisk
None
pkgs.unixtools.mount
None
pkgs.unixtools.write
None
pkgs.unixtools.column
None
pkgs.unixtools.getopt
None
pkgs.unixtools.logger
None
pkgs.unixtools.script
None
pkgs.unixtools.umount
None
pkgs.unixtools.hexdump
None
pkgs.unixtools.whereis
None
pkgs.util-linuxMinimal
Set of system utilities for Linux
pkgs.uutils-util-linux
Rust reimplementation of the util-linux project
-
nixos-unstable 0.0.1-unstable-2026-05-01
- nixpkgs-unstable 0.0.1-unstable-2026-05-01
- nixos-unstable-small 0.0.1-unstable-2026-05-01
-
nixos-26.05 0.0.1-unstable-2026-05-01
- nixos-26.05-small 0.0.1-unstable-2026-05-01
- nixpkgs-26.05-darwin 0.0.1-unstable-2026-05-01
pkgs.unixtools.util-linux
None
-
nixos-unstable 1003.1-2008
- nixpkgs-unstable 1003.1-2008
- nixos-unstable-small 1003.1-2008
-
nixos-26.05 1003.1-2008
- nixos-26.05-small 1003.1-2008
- nixpkgs-26.05-darwin 1003.1-2008
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@andir Andreas Rammhold <andreas@rammhold.de>
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
28 packages
- more
- wall
- eject
- mount
- logger
- umount
- hexdump
- libuuid
- utillinux
- libsmartcols
- unixtools.col
- unixtools.fsck
- unixtools.more
- unixtools.wall
- unixtools.eject
- unixtools.fdisk
- unixtools.mount
- unixtools.write
- unixtools.column
- unixtools.getopt
- unixtools.logger
- unixtools.script
- unixtools.umount
- unixtools.hexdump
- unixtools.whereis
- util-linuxMinimal
- uutils-util-linux
- unixtools.util-linux
- @LeSuisse accepted
- @LeSuisse published on GitHub
Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
References
Affected products
Matching in nixpkgs
Ignored packages (28)
pkgs.more
None
pkgs.wall
None
pkgs.eject
None
pkgs.mount
None
pkgs.logger
None
pkgs.umount
None
pkgs.hexdump
None
pkgs.libuuid
Set of system utilities for Linux
pkgs.utillinux
Set of system utilities for Linux
pkgs.libsmartcols
Set of system utilities for Linux
pkgs.unixtools.col
None
pkgs.unixtools.fsck
None
pkgs.unixtools.more
None
pkgs.unixtools.wall
None
pkgs.unixtools.eject
None
pkgs.unixtools.fdisk
None
pkgs.unixtools.mount
None
pkgs.unixtools.write
None
pkgs.unixtools.column
None
pkgs.unixtools.getopt
None
pkgs.unixtools.logger
None
pkgs.unixtools.script
None
pkgs.unixtools.umount
None
pkgs.unixtools.hexdump
None
pkgs.unixtools.whereis
None
pkgs.util-linuxMinimal
Set of system utilities for Linux
pkgs.uutils-util-linux
Rust reimplementation of the util-linux project
-
nixos-unstable 0.0.1-unstable-2026-05-01
- nixpkgs-unstable 0.0.1-unstable-2026-05-01
- nixos-unstable-small 0.0.1-unstable-2026-05-01
-
nixos-26.05 0.0.1-unstable-2026-05-01
- nixos-26.05-small 0.0.1-unstable-2026-05-01
- nixpkgs-26.05-darwin 0.0.1-unstable-2026-05-01
pkgs.unixtools.util-linux
None
-
nixos-unstable 1003.1-2008
- nixpkgs-unstable 1003.1-2008
- nixos-unstable-small 1003.1-2008
-
nixos-26.05 1003.1-2008
- nixos-26.05-small 1003.1-2008
- nixpkgs-26.05-darwin 1003.1-2008
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@andir Andreas Rammhold <andreas@rammhold.de>
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
7.9 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
28 packages
- more
- wall
- eject
- mount
- logger
- umount
- hexdump
- libuuid
- utillinux
- libsmartcols
- unixtools.col
- unixtools.fsck
- unixtools.more
- unixtools.wall
- unixtools.eject
- unixtools.fdisk
- unixtools.mount
- unixtools.write
- unixtools.column
- unixtools.getopt
- unixtools.logger
- unixtools.script
- unixtools.umount
- unixtools.hexdump
- unixtools.whereis
- util-linuxMinimal
- uutils-util-linux
- unixtools.util-linux
- @LeSuisse accepted
- @LeSuisse published on GitHub
Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
References
Affected products
Matching in nixpkgs
Ignored packages (28)
pkgs.more
None
pkgs.wall
None
pkgs.eject
None
pkgs.mount
None
pkgs.logger
None
pkgs.umount
None
pkgs.hexdump
None
pkgs.libuuid
Set of system utilities for Linux
pkgs.utillinux
Set of system utilities for Linux
pkgs.libsmartcols
Set of system utilities for Linux
pkgs.unixtools.col
None
pkgs.unixtools.fsck
None
pkgs.unixtools.more
None
pkgs.unixtools.wall
None
pkgs.unixtools.eject
None
pkgs.unixtools.fdisk
None
pkgs.unixtools.mount
None
pkgs.unixtools.write
None
pkgs.unixtools.column
None
pkgs.unixtools.getopt
None
pkgs.unixtools.logger
None
pkgs.unixtools.script
None
pkgs.unixtools.umount
None
pkgs.unixtools.hexdump
None
pkgs.unixtools.whereis
None
pkgs.util-linuxMinimal
Set of system utilities for Linux
pkgs.uutils-util-linux
Rust reimplementation of the util-linux project
-
nixos-unstable 0.0.1-unstable-2026-05-01
- nixpkgs-unstable 0.0.1-unstable-2026-05-01
- nixos-unstable-small 0.0.1-unstable-2026-05-01
-
nixos-26.05 0.0.1-unstable-2026-05-01
- nixos-26.05-small 0.0.1-unstable-2026-05-01
- nixpkgs-26.05-darwin 0.0.1-unstable-2026-05-01
pkgs.unixtools.util-linux
None
-
nixos-unstable 1003.1-2008
- nixpkgs-unstable 1003.1-2008
- nixos-unstable-small 1003.1-2008
-
nixos-26.05 1003.1-2008
- nixos-26.05-small 1003.1-2008
- nixpkgs-26.05-darwin 1003.1-2008
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@andir Andreas Rammhold <andreas@rammhold.de>
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>