Vulnerabilities
- CVSS
- 7.0 High
- Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- Risk score
- 56.0
- Published
- 2026-06-16
- Status
- Published
A flaw was found in util-linux. When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in the Linux kernel of Debian, allowing an attacker to potentially elevate their privileges. These vulnerabilities are present in older Debian versions and require immediate…
Advisories and references