An update that solves one vulnerability can now be installed.. # Security update for util-linux Announcement ID: SUSE-SU-2026:21727-1 Release Date: 2026-05-21T11:16:35Z Rating: moderate References: * bsc#1261606 Cross-References: * CVE-2026-27456 CVSS scores: * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for util-linux fixes the following issue * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-721=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * util-linux-2.39.3-7.1 * libuuid1-debuginfo-2.39.3-7.1 * util-linux-systemd-debuginfo-2.39.3-7.1 * libsmartcols1-debuginfo-2.39.3-7.1 * libblkid1-2.39.3-7.1 * util-linux-systemd-2.39.3-7.1 * util-linux-debugsource-2.39.3-7.1 * util-linux-systemd-debugsource-2.39.3-7.1 * libfdisk1-2.39.3-7.1 * libuuid1-2.39.3-7.1 * libmount1-debuginfo-2.39.3-7.1 * libsmartcols1-2.39.3-7.1 * libmount1-2.39.3-7.1 * libblkid1-debuginfo-2.39.3-7.1 * libfdisk1-debuginfo-2.39.3-7.1 * util-linux-debuginfo-2.39.3-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27456.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 . SUSE Linux Micro update fixes moderate security issue in util-linux relating to TOCTOU in loop device setup.. SUSE Linux Micro, Util-Linux Update, Moderate Security Fix. . LinuxSecurity.com Team
upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840b40ef4c 2026-04-10 00:59:15.834457+00:00 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 43 Version : 2.41.4 Release : 7.fc43 URL : https://en.wikipedia.org/wiki/Util-linux Summary : Collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files. CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Karel Zak - 2.41.4-7 - upgrade to upstream release v2.41.4 * Mon Jan 12 2026 Karel Zak - 2.41.3-9 - enable BuildRequires for parsers * Mon Jan 12 2026 Karel Zak - 2.41.3-8 - fix built on newgcc (bison based code and libblkid API) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840b40ef4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Moderate: util-linux and mount security update. Date: Thu, 13 Oct 2005 13:57:03 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 40,41 x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.