CVE-2026-78409: Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks

Published Aug 24, 2026
·
Updated

libmount's X-mount.subdir option on Linux >= 6.15 uses a detached-tree fast path (hooksubdir.c / hookmount.c). The configured subdirectory string is passed to opentree() with ATSYMLINKNOFOLLOW, but that flag does not block intermediate-component symlinks and does not provide RESOLVEBENEATH-style containment. An unprivileged user with an fstab-authorized X-mount.subdir= entry can therefore resolve outside the newly mounted filesystem (for example via an intermediate symlink to /etc, or via procfs self/root) and attach a host path at the fstab mountpoint. Restricted-user SUID mount(8) reproduction requires Linux >= 6.15; current HEAD gates that detached path on that kernel version. Introduced by ae19f7546ccb (2025-04-15); first released in util-linux v2.42. Affects v2.42 through v2.42.2 and current master. No upstream fix as of 2026-08-24. Reported upstream by Alex0Young. GHSA-8f2p-47x3-43mv.

Other sources

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to opentree() with ATSYMLINKNOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

MITRE

Affected Software

1 affected component
util-linux util-linux>=2.42<=2.42.2, >=undefined

Event History

Aug 24, 2026
Data Sourced
via Red Hat·06:38 PM
DescriptionSeverityAffected Software
Sep 2, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Exposure requires util-linux v2.42 through v2.42.2 or current master running on Linux 6.15 or later, where the detached-tree path is enabled. The system must also have an fstab-authorized X-mount.subdir= entry available to an unprivileged user.

2

What access does an attacker need?

An attacker needs local unprivileged access and authorization to use a relevant fstab entry. No user interaction is required, but exploitation depends on a subdirectory path that traverses an intermediate symlink outside the newly mounted filesystem.

3

What is the practical impact of successful exploitation?

The attacker can cause a host path, such as one reached through an intermediate symlink to /etc or through procfs self/root, to be attached at the fstab mountpoint. This can result in high confidentiality, integrity, and availability impact.

4

How can administrators identify potentially affected configurations?

Check whether the host runs Linux 6.15 or later and uses an affected util-linux release, then review fstab-authorized entries for X-mount.subdir=. Entries accessible to restricted users are the relevant exposure point.

5

Is an upstream fix available?

No upstream fix was available as of 2026-08-24.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203