news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-53613

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.0 High
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk score
56.0
Published
2026-06-16
Status
Published

A flaw was found in util-linux. When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.

Weaknesses

CWE-367

Coverage 1

Advisories and references