Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: util-linux

Found 8 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2026-76642
8.5 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
util-linux libmount Privilege Escalation via Failed Mount Helper

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

Affected products

util-linux
  • <2.41.6
  • <2.42.3

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Published
Permalink CVE-2026-78409
7.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    11 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • util-linux
    • libsmartcols
  • @LeSuisse restored package util-linux
  • @LeSuisse ignored
    18 packages
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Published
Permalink CVE-2026-78408
7.9 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Published
Permalink CVE-2026-78410
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Untriaged
Permalink CVE-2026-13595
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 2 months, 2 weeks ago Activity log
  • Created suggestion
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Affected products

rhcos
util-linux

Matching in nixpkgs

pkgs.more

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.wall

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.eject

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.mount

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.logger

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.umount

None

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.libuuid

Set of system utilities for Linux

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.utillinux

Set of system utilities for Linux

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.util-linux

Set of system utilities for Linux

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42

pkgs.libsmartcols

Set of system utilities for Linux

  • nixos-unstable 2.42
    • nixpkgs-unstable 2.42
    • nixos-unstable-small 2.42
  • nixos-26.05 2.42
    • nixos-26.05-small 2.42
    • nixpkgs-26.05-darwin 2.42
Published
Permalink CVE-2026-3184
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    27 packages
    • more
    • wall
    • mount
    • eject
    • umount
    • logger
    • hexdump
    • libuuid
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: access control bypass due to improper hostname canonicalization

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.

References

Ignored references (1)

Affected products

rhcos
util-linux

Matching in nixpkgs

Ignored packages (27)

Package maintainers

Patch: https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984
Untriaged
Permalink CVE-2026-27456
4.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Affected products

util-linux
  • ==< 2.41.4

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2025-14104
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 7 months, 1 week ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package uutils-util-linux
Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

References

Affected products

rhcos
util-linux
  • *
  • <2.41.3
util-linux-ng
rhceph/rhceph-7-rhel9
  • *
rhceph/rhceph-8-rhel9
  • *
rhui5/installer-rhel9
  • *
insights-proxy/insights-proxy-container-rhel9
  • *

Matching in nixpkgs

Ignored packages (1)

Package maintainers