This update for util-linux fixes the following issues:
Security issue:
* CVE-2026-3184: access control bypass due to improper hostname
canonicalization in `login` (bsc#1258859).
Non security issues:
* recognize fuse "portal" as a virtual file system (bsc#1234736).
* fdisk: fix possible partition overlay and data corruption if EBR gap is
missing (bsc#1222465).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-987=1
* SUSE Linux Enterprise Micro 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-987=1
* SUSE Linux Enterprise Micro for Rancher 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-987=1
* openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586)
* libfdisk-devel-2.36.2-150300.4.58.1
* python3-libmount-debuginfo-2.36.2-150300.4.58.1
* libblkid-devel-static-2.36.2-150300.4.58.1
* libsmartcols-devel-static-2.36.2-150300.4.58.1
* libfdisk-devel-static-2.36.2-150300.4.58.1
* uuidd-debuginfo-2.36.2-150300.4.58.1
* libmount-devel-static-2.36.2-150300.4.58.1
* python3-libmount-2.36.2-150300.4.58.1
* util-linux-debugsource-2.36.2-150300.4.58.1
* util-linux-systemd-2.36.2-150300.4.58.1
* libuuid1-debuginfo-2.36.2-150300.4.58.1
* uuidd-2.36.2-150300.4.58.1
* libblkid-devel-2.36.2-150300.4.58.1
* libblkid1-2.36.2-150300.4.58.1
* util-linux-systemd-debuginfo-2.36.2-150300.4.58.1
* libuuid1-2.36.2-150300.4.58.1
* util-linux-systemd-debugsource-2.36.2-150300.4.58.1
* libfdisk1-debuginfo-2.36.2-150300.4.58.1
* libuuid-devel-2.36.2-150300.4.58.1
* libmount1-2.36.2-150300.4.58.1
* libsmartcols1-2.36.2-150300.4.58.1
* util-linux-2.36.2-150300.4.58.1
* util-linux-debuginfo-2.36.2-150300.4.58.1
*...
Read the Full Advisory* bsc#1222465
* bsc#1234736
* bsc#1258859
## References:
* https://www.suse.com/security/cve/CVE-2026-3184.html
* https://bugzilla.suse.com/show_bug.cgi?id=1222465
* https://bugzilla.suse.com/show_bug.cgi?id=1234736
* https://bugzilla.suse.com/show_bug.cgi?id=1258859
Get the latest Linux and open source security news straight to your inbox.