CVE-2026-27456 identifies a Time-of-Check-Time-of-Use (TOCTOU) race condition in the SUID /usr/bin/mount utility of util-linux, affecting versions prior to 2.41.4 on virtually all Linux distributions. This local vulnerability, rated Medium (CVSS 4.7, AC:H), allows an unprivileged user to gain unauthorized read access to root-protected files or block devices. Exploitation requires specific /etc/fstab configurations and write permissions to a target directory. Currently, there are no known public exploits, and it is not listed as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.41.4CPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.