Security: util-linux/util-linux
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
BannerEscape: escape sequence injection in wall(1)/write(1) message headers via hostnameGHSA-4558-p62c-vv5v published
Sep 2, 2026 by karelzakLow -
nsenter --join-cgroup leaks root cgroup migration authorityGHSA-55fx-f4gg-cfhj published
Sep 2, 2026 by karelzakHigh -
Failed external mount helper still triggers privileged X-mount post-hooks, enabling deterministic local privilege escalationGHSA-m25x-3hj9-m26f published
Sep 2, 2026 by karelzakHigh -
`X-mount.subdir` detached-tree resolution can escape via intermediate symlinks and procfs pathsGHSA-8f2p-47x3-43mv published
Sep 2, 2026 by karelzakHigh -
Restricted bind mounts do not pin the source, allowing `X-mount.owner/group/mode` redirectionGHSA-rh77-686x-2f2m published
Sep 2, 2026 by karelzakHigh -
Integer Overflow or Wraparound in libblkid/src/partitions/dos.cGHSA-h4rw-gv36-wmp5 published
Jun 16, 2026 by karelzakHigh -
Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable — nosuid/noexec Bypass in SUID mount(8)GHSA-67r7-8m5w-22wx published
Jun 16, 2026 by karelzakHigh -
Local Privilege Escalation via TOCTOU in mount(8) — Target Path RedirectionGHSA-8gj5-72r3-428g published
Jun 16, 2026 by karelzakHigh -
Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chownGHSA-g8wm-75wr-g2vh published
Jun 16, 2026 by karelzakHigh -
TOCTOU Race Condition in util-linux mount(8) - Loop Device SetupGHSA-qq4x-vfq4-9h9g published
Apr 1, 2026 by karelzakModerate
Learn more about advisories related to util-linux/util-linux in the GitHub Advisory Database