Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-76642 — util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks CVE-2026-78408 — util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority CVE-2026-78409 — util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks CVE-2026-78410 — util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
🎯 Affected products4
- Red Hat Hardened Images
- util-linux-main@aarch64 as a component of Red Hat Hardened Images
- util-linux-main@src as a component of Red Hat Hardened Images
- util-linux-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, avoid combining the user (or users) fstab option with X-mount.idmap or X-mount.owner/group/mode on entries that invoke an external mount.<type> helper. Administrators can also remove or restrict user-mountable fstab entries that specify those X-mount.* options. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not run nsenter --join-cgroup (including nsenter --target PID --all --join-cgroup) against untrusted processes or namespaces. The fix closes the cgroup.procs descriptor immediately after joining, and opens it with O_CLOEXEC. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab entries that specify X-mount.subdir. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab bind or rbind entries that also specify X-mount.owner, X-mount.group, or X-mount.mode, especially when the bind source is below a user-writable ancestor.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:63162
- externalhttps://access.redhat.com/security/cve/CVE-2026-76642
- externalhttps://access.redhat.com/security/cve/CVE-2026-78408
- externalhttps://access.redhat.com/security/cve/CVE-2026-78409
- externalhttps://access.redhat.com/security/cve/CVE-2026-78410
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63162.json