PatchSiren

util-linux CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM util-linux CVE published 2026-04-03

CVE-2026-27456

A Time-of-Check-Time-of-Use (TOCTOU) vulnerability was identified in the SUID binary /usr/bin/mount from util-linux prior to version 2.41.4. This issue allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop opti [truncated]