Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78410— Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译: 在 util-linux 中发现了一个缺陷:受限的 bind 挂载从 中获取源路径,但并未在执行需要特权的挂载操作之前固定(pin)该源路径。一个本地的非特权用户若能替换被授权的源路径或其可写的上级目录,就可以将 SUID 的 命令重定向到主机的另一个目录。如果 条目同时设置了 、 或 选项,root 用户将会对重定向后的 inode 修改其所有权(owner/group)或访问权限(mode)。

CVSS 7.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78410

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-78410

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78410

登录查看更多情报信息。

Vendor Advisories for CVE-2026-78410 (2)

Other References for CVE-2026-78410 (1)

Same Patch Batch · Red Hat · 2026-09-02 · 7 CVEs total

CVE-2026-78408 7.9 HIGH Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-84838 7.8 HIGH Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()
CVE-2026-84837 7.8 HIGH Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path
CVE-2026-78409 7.0 HIGH Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediat
CVE-2026-82968 6.4 MEDIUM Keycloak-services: keycloak-services: cross-session email verification proof not bound to
CVE-2026-53683 4.3 MEDIUM Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

IV. Related Vulnerabilities

V. Comments for CVE-2026-78410

No comments yet


Leave a comment