The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HKernel Util Linux
APPKernel2.27≤ 2.26.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2018-7738HIGH7.8same product
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell...
CVE-2014-9114HIGH7.8same product
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
CVE-2016-2779HIGH7.8same product
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, whi...
CVE-2007-5191HIGH7.2same product
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and ...
CVE-2026-13595MEDIUM6.8same product
W bibliotece libblkid z util-linux odkryto lukę. Podczas zagnieżdżonego sondowania partycji, narzędzia do anal...