Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 03 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation. | |
| Title | util-linux libmount Privilege Escalation via Failed Mount Helper | |
| First Time appeared |
Kernel
Kernel util-linux |
|
| Weaknesses | CWE-390 | |
| CPEs | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kernel
Kernel util-linux |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:00:29.374Z
Reserved: 2026-08-19T14:53:58.575Z
Link: CVE-2026-76642
Updated: 2026-09-03T14:00:05.019Z
Status : Received
Published: 2026-09-03T13:06:08.440
Modified: 2026-09-03T13:06:08.440
Link: CVE-2026-76642
OpenCVE Enrichment
Updated: 2026-09-03T13:15:04Z