Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE Linux Micro 6.0 Util-Linux Moderate TOCTOU Vulnerability 2026-21727-1

An update that solves one vulnerability can now be installed.. # Security update for util-linux Announcement ID: SUSE-SU-2026:21727-1 Release Date: 2026-05-21T11:16:35Z Rating: moderate References: * bsc#1261606 Cross-References: * CVE-2026-27456 CVSS scores: * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for util-linux fixes the following issue * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-721=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * util-linux-2.39.3-7.1 * libuuid1-debuginfo-2.39.3-7.1 * util-linux-systemd-debuginfo-2.39.3-7.1 * libsmartcols1-debuginfo-2.39.3-7.1 * libblkid1-2.39.3-7.1 * util-linux-systemd-2.39.3-7.1 * util-linux-debugsource-2.39.3-7.1 * util-linux-systemd-debugsource-2.39.3-7.1 * libfdisk1-2.39.3-7.1 * libuuid1-2.39.3-7.1 * libmount1-debuginfo-2.39.3-7.1 * libsmartcols1-2.39.3-7.1 * libmount1-2.39.3-7.1 * libblkid1-debuginfo-2.39.3-7.1 * libfdisk1-debuginfo-2.39.3-7.1 * util-linux-debuginfo-2.39.3-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27456.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 . SUSE Linux Micro update fixes moderate security issue in util-linux relating to TOCTOU in loop device setup.. SUSE Linux Micro, Util-Linux Update, Moderate Security Fix. . LinuxSecurity.com Team

Calendar 2 May 22, 2026 SuSE
89

Fedora 43 util-linux Important SUID Symlink Attack CVE-2026-27456

upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840b40ef4c 2026-04-10 00:59:15.834457+00:00 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 43 Version : 2.41.4 Release : 7.fc43 URL : https://en.wikipedia.org/wiki/Util-linux Summary : Collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files. CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Karel Zak - 2.41.4-7 - upgrade to upstream release v2.41.4 * Mon Jan 12 2026 Karel Zak - 2.41.3-9 - enable BuildRequires for parsers * Mon Jan 12 2026 Karel Zak - 2.41.3-8 - fix built on newgcc (bison based code and libblkid API) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840b40ef4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes security flaws in util-linux for Fedora 43, addressing symlink attacks and integer overflow issues.. Fedora update, util-linux security, mount symlink attack, integer overflow, system utilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 10, 2026 Important Fedora
200

Scientific Linux: 2005-2876 Moderate: Util-Linux and Mount Security Fix

Moderate: util-linux and mount security update. Date: Thu, 13 Oct 2005 13:57:03 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 40,41 x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. The following ERRATA for SL 40,41 x86_64 are now available from: Synopsis: Moderate: util-linux and mount security update Advisory ID: RHSA-2005:782-01 CVE Names: CAN-2005-2876 CAN-2001-1494 util-linux-2.12a-16.EL4.12.x86_64.rpm audit-libs-1.0.3-6.EL4.i386.rpm audit-libs-1.0.3-6.EL4.x86_64.rpm audit-libs-devel-1.0.3-6.EL4.x86_64.rpm pam-0.77-66.11.i386.rpm pam-0.77-66.11.x86_64.rpm pam-devel-0.77-66.11.i386.rpm pam-devel-0.77-66.11.x86_64.rpm -Connie Sieh -Troy Dawson . Important security patches rolled out for util-linux and mount in Scientific Linux versions 40 and 41.. util-linux, scientific linux, security update, mount, moderate. . LinuxSecurity.com Team

Calendar 2 Oct 13, 2005 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here