Package "libuuid1-dbgsym"
| Name: |
libuuid1-dbgsym
|
Description: |
debug symbols for libuuid1
|
| Latest version: |
2.41.3-3ubuntu2.2 |
| Release: |
resolute (26.04) |
| Level: |
updates |
| Repository: |
universe |
| Head package: |
util-linux |
Links
Download "libuuid1-dbgsym"
Other versions of "libuuid1-dbgsym" in Resolute
Changelog
|
util-linux (2.41.3-3ubuntu2.2) resolute-security; urgency=medium
* SECURITY UPDATE: Heap use-after-free via crafted block device image
- debian/patches/CVE-2026-13595.patch: libblkid: fix use-after-free in
nested partition probing in libblkid/src/partitions/partitions.c.
- CVE-2026-13595
* SECURITY UPDATE: TOCTOU in mount utility
- debian/patches/CVE-2026-27456.patch: loopdev: add LOOPDEV_FL_NOFOLLOW to
prevent symlink attacks in include/loopdev.h, lib/loopdev.c,
libmount/src/hook_loopdev.c.
- CVE-2026-27456
* SECURITY UPDATE: Improper hostname canonicalization in login
- debian/patches/CVE-2026-3184.patch: login: use original FQDN for PAM_RHOST
in login-utils/login.c.
- CVE-2026-3184
* SECURITY UPDATE: Local Privilege Escalation via TOCTOU in mount
- debian/patches/CVE-2026-53612.patch: libmount: use fd-based fchownat/chmod
in hook_owner in libmount/src/hook_owner.c.
- CVE-2026-53612
* SECURITY UPDATE: Another local Privilege Escalation via TOCTOU in mount
- debian/patches/CVE-2026-53613-pre1.patch: lib/fileutils: add
ul_open_no_symlinks() in configure.ac, include/fileutils.h,
lib/fileutils.c, meson.build.
- debian/patches/CVE-2026-53613.patch: libmount: add fd_target to context
for TOCTOU prevention in libmount/src/context.c,
libmount/src/context_mount.c, libmount/src/hook_mount.c,
libmount/src/hook_mount_legacy.c, libmount/src/mountP.h.
- CVE-2026-53613
* SECURITY UPDATE: Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2
Environment Variable
- debian/patches/CVE-2026-53614.patch: libmount: fix SUID bypass via
LIBMOUNT_FORCE_MOUNT2 and legacy mount path in libmount/src/hook_mount.c,
libmount/src/hook_mount_legacy.c.
- CVE-2026-53614
* SECURITY UPDATE: Integer Overflow or Wraparound in dos.c
- debian/patches/CVE-2026-53615.patch: libblkid: dos: validate EBR data and
links within extended partition in libblkid/src/partitions/dos.c.
- CVE-2026-53615
* debian/patches/tests-fincore-force-the-use-of-GNU-dd-over-uutils.patch:
fix ftbfs on arm64 and armhf.
-- Marc Deslauriers Wed, 19 Aug 2026 10:23:36 -0400
|
| CVE-2026-13595 |
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers |
| CVE-2026-27456 |
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified |
| CVE-2026-3184 |
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the suppl |
| CVE-2026-53612 |
Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown |
| CVE-2026-53613 |
Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection |
| CVE-2026-53614 |
Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) |
| CVE-2026-53615 |
Integer Overflow or Wraparound in libblkid/src/partitions/dos.c |
|
About
-
Send Feedback to @ubuntu_updates