CRITICAL🇵🇱 Wersja polska

CVE-2015-5224

CVSS 9.8v3.1pub. 2017-08-23upd. 2026-05-13

The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Kernel Util Linux

    APP
    Kernel
    2.27≤ 2.26.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-7738HIGH7.8same product

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell...

CVE-2014-9114HIGH7.8same product

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

CVE-2016-2779HIGH7.8same product

runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, whi...

CVE-2007-5191HIGH7.2same product

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and ...

CVE-2026-13595MEDIUM6.8same product

W bibliotece libblkid z util-linux odkryto lukę. Podczas zagnieżdżonego sondowania partycji, narzędzia do anal...