UbuntuUpdates.org

Package "libuuid1"

Name: libuuid1

Description:

Universally Unique ID library

Latest version: 2.37.2-4ubuntu3.6
Release: jammy (22.04)
Level: updates
Repository: main
Head package: util-linux
Homepage: https://www.kernel.org/pub/linux/utils/util-linux/

Links


Download "libuuid1"


Other versions of "libuuid1" in Jammy

Repository Area Version
base main 2.37.2-4ubuntu3
security main 2.37.2-4ubuntu3.6

Changelog

Version: 2.37.2-4ubuntu3.6 2026-08-31 16:07:33 UTC

util-linux (2.37.2-4ubuntu3.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap use-after-free via crafted block device image
    - debian/patches/CVE-2026-13595.patch: libblkid: fix use-after-free in
      nested partition probing in libblkid/src/partitions/partitions.c.
    - CVE-2026-13595
  * SECURITY UPDATE: TOCTOU in mount utility
    - debian/patches/CVE-2026-27456.patch: loopdev: add LOOPDEV_FL_NOFOLLOW to
      prevent symlink attacks in include/loopdev.h, lib/loopdev.c,
      libmount/src/context_loopdev.c.
    - CVE-2026-27456
  * SECURITY UPDATE: Another local Privilege Escalation via TOCTOU in mount
    - debian/patches/CVE-2026-53613-pre1.patch: lib/fileutils: add
      ul_open_no_symlinks() in include/fileutils.h, lib/fileutils.c.
    - debian/patches/CVE-2026-53613.patch: libmount: add fd_target to context
      for TOCTOU prevention in libmount/src/context.c,
      libmount/src/context_mount.c, libmount/src/mountP.h.
    - CVE-2026-53613
  * SECURITY UPDATE: Integer Overflow or Wraparound in dos.c
    - debian/patches/CVE-2026-53615.patch: libblkid: dos: validate EBR data and
      links within extended partition in libblkid/src/partitions/dos.c.
    - CVE-2026-53615

 -- Marc Deslauriers Wed, 19 Aug 2026 13:43:12 -0400

Source diff to previous version
CVE-2026-13595 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers
CVE-2026-27456 util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified
CVE-2026-53613 Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection
CVE-2026-53615 Integer Overflow or Wraparound in libblkid/src/partitions/dos.c

Version: 2.37.2-4ubuntu3.5 2026-03-13 12:07:58 UTC

  util-linux (2.37.2-4ubuntu3.5) jammy-security; urgency=medium

  * d/p/ubuntu/su-pty-drop-caps.patch: harden 'su --pty' to temporarily lower
    capabilities while proxying between stdin/stdout and the pty master. This
    is to avoid su from being used to exploit kernel vulnerabilities.

 -- Luci Stanescu <email address hidden> Fri, 06 Mar 2026 18:10:04 +0200

Source diff to previous version

Version: 2.37.2-4ubuntu3.4 2024-04-10 14:31:40 UTC

  util-linux (2.37.2-4ubuntu3.4) jammy-security; urgency=medium

  * SECURITY UPDATE: Improper neutralization of escape sequences in wall
    - debian/rules: build with --disable-use-tty-group to properly remove
      setgid bit from both wall and write.
    - CVE-2024-28085

 -- Marc Deslauriers <email address hidden> Tue, 09 Apr 2024 11:32:56 -0400

Source diff to previous version
CVE-2024-28085 escape sequence Injection in wall

Version: 2.37.2-4ubuntu3.3 2024-03-27 18:07:10 UTC

  util-linux (2.37.2-4ubuntu3.3) jammy-security; urgency=medium

  * SECURITY UPDATE: Improper neutralization of escape sequences in wall
    - debian/patches/upstream/CVE-2024-28085-pre1.patch: correctly handle
      wide characters in include/carefulputc.h, login-utils/last.c,
      term-utils/write.c.
    - debian/patches/upstream/CVE-2024-28085-pre2.patch: convert homebrew
      buffering to open_memstream() in term-utils/wall.c.
    - debian/patches/upstream/CVE-2024-28085-pre3.patch: use
      fputs_careful() in include/carefulputc.h, login-utils/last.c,
      term-utils/wall.c, term-utils/write.c.
    - debian/patches/upstream/CVE-2024-28085.patch: consolidate output on
      the terminal in term-utils/wall.c.
    - CVE-2024-28085

 -- Marc Deslauriers <email address hidden> Fri, 22 Mar 2024 08:25:19 -0400

CVE-2024-28085 escape sequence Injection in wall



About   -   Send Feedback to @ubuntu_updates