Kernel
Kernel Util-linux: vulnerabilidades y CVE
Kernel Util-linux tiene 18 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13595 | Media (5.3) | 0.17% | — | 29 jun 2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically… |
| CVE-2026-27456 | Media (4.7) | 0.12% | — | 3 abr 2026 | util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary,… |
| CVE-2026-3184 | Media (5.3) | 0.62% | — | 3 abr 2026 | A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker… |
| CVE-2024-28085 | Baja (3.3) | 2.2% | — | 27 mar 2024 | wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked,… |
| CVE-2020-21583 | Media (6.7) | 0.55% | — | 22 ago 2023 | An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date. |
| CVE-2021-3996 | Media (5.5) | 0.63% | — | 23 ago 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users'… |
| CVE-2021-3995 | Media (5.5) | 0.63% | — | 23 ago 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems… |
| CVE-2022-0563 | Media (5.5) | 0.43% | — | 21 feb 2022 | A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library… |
| CVE-2021-37600 | Media (5.5) | 0.66% | — | 30 jul 2021 | An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this… |
| CVE-2018-7738 | Alta (7.8) | 0.43% | — | 7 mar 2018 | In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different… |
| CVE-2015-5224 | Crítica (9.8) | 4.5% | — | 23 ago 2017 | The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks. |
| CVE-2016-5011 | Media (4.6) | 0.47% | — | 11 abr 2017 | The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with… |
| CVE-2014-9114 | Alta (7.8) | 0.64% | — | 31 mar 2017 | Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. |
| CVE-2016-2779 | Alta (7.8) | 0.39% | — | 7 feb 2017 | runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. |
| CVE-2015-5218 | Baja (2.1) | 0.61% | — | 9 nov 2015 | Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable. |
| CVE-2013-0157 | Baja (2.1) | 0.38% | — | 21 ene 2014 | (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2)… |
| CVE-2007-5191 | Alta (7.2) | 0.44% | — | 4 oct 2007 | mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. |
| CVE-2001-1494 | Media (5.5) | 0.43% | — | 31 dic 2001 | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script… |