Detection of Error Condition Without Action in Util-linux - CVE-2026-76642
Published: September 2, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to incorrect status handling in libmount post-mount hooks when processing a failed external mount helper. A local user can trigger a nonzero helper exit for a root-controlled fstab entry with X-mount.idmap to escalate privileges.
Exploitation requires SUID-root mount(8), a usable root-controlled fstab entry, a failed external mount helper, and an idmap-capable filesystem target.