Vulnerabilities
- CVSS
- 7.0 High
- Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- Risk score
- 56.0
- Published
- 2026-06-16
- Status
- Published
A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in the Linux kernel of Debian, allowing an attacker to potentially elevate their privileges. These vulnerabilities are present in older Debian versions and require immediate…
Advisories and references