Multiple Vulnerabilities Discovered in Ubuntu's util-linux

Multiple Vulnerabilities Discovered in Ubuntu's util-linux

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

On August 31, 2026, Ubuntu announced several vulnerabilities in the util-linux package affecting Ubuntu 24.04 LTS and 26.04 LTS. Notable issues include a heap use-after-free vulnerability in libblkid (CVE-2026-13595), a time-of-check-time-of-use vulnerability in the mount utility (CVE-2026-27456), and a hostname canonicalization issue in the login utility (CVE-2026-3184). These vulnerabilities could allow local and remote attackers to access sensitive information or bypass access controls. The vulnerabilities were disclosed and are currently addressed with updates available for affected systems. Users are advised to update their systems to mitigate these risks.

Key Points: • Three critical vulnerabilities were found in util-linux affecting Ubuntu 24.04 and 26.04 LTS. • CVE-2026-13595 allows potential information disclosure via crafted block device images. • Immediate system updates are recommended to address these vulnerabilities.

Timeline

2026-04-03
CVE-2026-27456 and CVE-2026-3184 published
Two vulnerabilities were published, including a time-of-check-time-of-use issue in mount and a hostname canonicalization issue in login.
Ubuntu
2026-06-29
CVE-2026-13595 published
A heap use-after-free vulnerability in libblkid was disclosed, allowing potential denial of service or information disclosure.
Ubuntu
2026-08-31
Ubuntu announces vulnerabilities in util-linux
Ubuntu released a security notice detailing multiple vulnerabilities in util-linux, urging users to update their systems.
Linuxsecurity