{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akernel_orgutil_linux/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kernel_org:util_linux:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-78410"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["util-linux"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","linux","local-exploit"],"_cs_type":"advisory","_cs_vendors":["Kernel.org"],"content_html":"\u003cp\u003eCVE-2026-78410 describes a critical security flaw in the util-linux package, specifically within the handling of restricted bind mounts. The vulnerability stems from the mount(8) command failing to properly pin the source path defined in the fstab file before executing the mount operation. This creates a time-of-check to time-of-use (TOCTOU) race condition. An unprivileged local user who has the ability to manipulate the directory structure or replace the source path can redirect the mount(8) operation to an arbitrary directory on the host. When the fstab entry includes administrative mount options such as X-mount.owner, X-mount.group, or X-mount.mode, the SUID-root mount binary inadvertently applies these permissions changes to the redirected target directory, leading to full privilege escalation. This issue impacts systems where users have permission to trigger mounts defined in fstab.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unprivileged local attacker to elevate their privileges to root by changing the ownership or permissions of sensitive files or directories on the system. This can lead to total system compromise, unauthorized data access, and persistence. The vulnerability affects all systems utilizing the vulnerable version of the util-linux package, particularly those configured with user-accessible mount points in fstab.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching the util-linux package across all Linux distributions as soon as security updates are provided by upstream maintainers or OS vendors. Monitor for unauthorized usage of mount(8) by non-root users in local environments, specifically looking for process executions involving fstab-defined mount points and the use of user-controlled mount options.\u003c/p\u003e\n","date_modified":"2026-09-02T17:16:02Z","date_published":"2026-09-02T17:16:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-util-linux-privesc/","summary":"A vulnerability in util-linux allows unprivileged local users to perform arbitrary bind mounts and change file ownership or permissions by exploiting a race condition in SUID mount(8) handling of fstab entries.","title":"Local Privilege Escalation in util-linux via Race Condition","url":"https://feed.craftedsignal.io/briefs/2026-09-util-linux-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kernel_org:util_linux:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}