news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-53612

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.0 High
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk score
56.0
Published
2026-06-16
Status
Published

A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.

Weaknesses

CWE-367

Coverage 1

Advisories and references