๐Ÿ” CVE Alert

CVE-2026-76642

HIGH 7.8

util-linux libmount Privilege Escalation via Failed Mount Helper

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

CWE CWE-390
Vendor util-linux
Product util-linux
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for util-linux util-linux

Be the first to know when new high vulnerabilities affecting util-linux util-linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

util-linux / util-linux
2.39 < 2.41.6 2.42 < 2.42.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f github.com: https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf github.com: https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a github.com: https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc github.com: https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476 github.com: https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892 github.com: https://github.com/util-linux/util-linux vulncheck.com: https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper

Credits

๐Ÿ” Andreas Gabriel Berbescu ๐Ÿ” Ivan Redondo Plaza