Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: util-linux

Found 5 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-76642
8.5 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
util-linux libmount Privilege Escalation via Failed Mount Helper

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

Affected products

util-linux
  • <2.41.6
  • <2.42.3

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Permalink CVE-2026-78409
7.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    11 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • util-linux
    • libsmartcols
  • @LeSuisse restored package util-linux
  • @LeSuisse ignored
    18 packages
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Permalink CVE-2026-78408
7.9 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Permalink CVE-2026-78410
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    28 packages
    • more
    • wall
    • eject
    • mount
    • logger
    • umount
    • hexdump
    • libuuid
    • utillinux
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

Affected products

rhcos
util-linux
rhel8/flatpak-sdk
rhel8/flatpak-runtime

Matching in nixpkgs

Ignored packages (28)

pkgs.libuuid

Set of system utilities for Linux

pkgs.utillinux

Set of system utilities for Linux

Package maintainers

Permalink CVE-2026-3184
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    27 packages
    • more
    • wall
    • mount
    • eject
    • umount
    • logger
    • hexdump
    • libuuid
    • libsmartcols
    • unixtools.col
    • unixtools.fsck
    • unixtools.more
    • unixtools.wall
    • unixtools.eject
    • unixtools.fdisk
    • unixtools.mount
    • unixtools.write
    • unixtools.column
    • unixtools.getopt
    • unixtools.logger
    • unixtools.script
    • unixtools.umount
    • unixtools.hexdump
    • unixtools.whereis
    • util-linuxMinimal
    • uutils-util-linux
    • unixtools.util-linux
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Util-linux: util-linux: access control bypass due to improper hostname canonicalization

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.

References

Ignored references (1)

Affected products

rhcos
util-linux

Matching in nixpkgs

Ignored packages (27)

Package maintainers

Patch: https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984