Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27456

23
FAUCET Score

CVE-2026-27456 identifies a Time-of-Check-Time-of-Use (TOCTOU) race condition in the SUID /usr/bin/mount utility of util-linux, affecting versions prior to 2.41.4 on virtually all Linux distributions. This local vulnerability, rated Medium (CVSS 4.7, AC:H), allows an unprivileged user to gain unauthorized read access to root-protected files or block devices. Exploitation requires specific /etc/fstab configurations and write permissions to a target directory. Currently, there are no known public exploits, and it is not listed as actively exploited.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.41.4CPE matchmatch criteria
cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 20th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 util-linux 2.40.2-3 on Azure Linux 3.0Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: 20786-17086Fixed in: 2.37.4-11
microsoftpatch availablevia msrc
Product: cbl2 util-linux 2.37.4-10 on CBL Mariner 2.0Fixed in: 2.37.4-11
microsoftpatch availablevia msrc
Product: 20804-17084Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: 21213-17084Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: azl3 util-linux 2.40.2-4 on Azure Linux 3.0Fixed in: 2.40.2-4

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-27456Moderate

util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup

Apr 2, 2026

References

github.com / util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4
Patch
github.com / util-linux/util-linux/releases/tag/v2.41.4
Product
github.com / util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g
ExploitVendor Advisory