RHSA-2026:63162HighCVSS 7.9

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
September 3, 2026
Last Modified
September 7, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-76642 — util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks CVE-2026-78408 — util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority CVE-2026-78409 — util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks CVE-2026-78410 — util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection

🎯 Affected products4

  • Red Hat Hardened Images
  • util-linux-main@aarch64 as a component of Red Hat Hardened Images
  • util-linux-main@src as a component of Red Hat Hardened Images
  • util-linux-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, avoid combining the user (or users) fstab option with X-mount.idmap or X-mount.owner/group/mode on entries that invoke an external mount.<type> helper. Administrators can also remove or restrict user-mountable fstab entries that specify those X-mount.* options. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not run nsenter --join-cgroup (including nsenter --target PID --all --join-cgroup) against untrusted processes or namespaces. The fix closes the cgroup.procs descriptor immediately after joining, and opens it with O_CLOEXEC. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab entries that specify X-mount.subdir. Workaround: Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not allow unprivileged /etc/fstab bind or rbind entries that also specify X-mount.owner, X-mount.group, or X-mount.mode, especially when the bind source is below a user-writable ancestor.

🔗 References (8)