{"id":"CVE-2026-76642","summary":"util-linux libmount Privilege Escalation via Failed Mount Helper","details":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","aliases":["GHSA-m25x-3hj9-m26f"],"modified":"2026-09-09T03:47:15.837784641Z","published":"2026-09-03T10:54:08.150Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-390"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76642.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76642.json"},{"type":"ADVISORY","url":"https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"},{"type":"FIX","url":"https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a"},{"type":"FIX","url":"https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc"},{"type":"FIX","url":"https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf"},{"type":"PACKAGE","url":"https://github.com/util-linux/util-linux"},{"type":"ARTICLE","url":"https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476"},{"type":"ARTICLE","url":"https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/util-linux/util-linux","events":[{"introduced":"2dccaae42bfdd0f1e34da11f2023480655308e1b"},{"fixed":"02822c9374fc72d38baf8a1f859eb0813970bf3f"},{"introduced":"0a7dfc376192e8fb1e7bdb2d0c90d8b9b173a42b"},{"fixed":"6f20a5defcf9066d4d2af372424a1576bd3d495d"}],"database_specific":{"extracted_events":[{"introduced":"2.39"},{"fixed":"2.41.6"},{"introduced":"2.42"},{"fixed":"2.42.3"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.42.2","v2.41.5","v2.41.4","v2.42.1","v2.42","v2.42-rc2","v2.42-rc1","v2.41.3","v2.41.2","v2.41.2-rc1","v2.41.1","v2.41","v2.41-rc2","v2.41-rc1","v2.42-start"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-76642.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}