Util Linux
Vendor:
First CVE: Dec 31, 2001 · Active for 24 years
18
Total CVEs
More Total CVEs than 93% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Util Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Jun 29, 2026
25 days ago
CVE Severity & Scoring
Util Linux18 CVEs
17%
56%
22%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (66.7%)
Network2 (11.1%)
Unknown3 (16.7%)
Physical1 (5.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (77.8%)
High1 (5.6%)
Unknown3 (16.7%)
User Interaction
None14 (77.8%)
Unknown3 (16.7%)
Required1 (5.6%)
Privileges Required
Low9 (50.0%)
High1 (5.6%)
None5 (27.8%)
Unknown3 (16.7%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13595MEDIUM A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent | Jun 29, 2026 | 6.8 | 34 | NO | NO |
CVE-2018-7738HIGH In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount co | Mar 7, 2018 | 7.8 | 26 | NO | NO |
CVE-2014-9114HIGH Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. | Mar 31, 2017 | 7.8 | 26 | NO | NO |
CVE-2026-3184MEDIUM A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before sett | Apr 3, 2026 | 5.3 | 25 | NO | NO |
CVE-2015-5224CRITICAL The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks. | Aug 23, 2017 | 9.8 | 25 | NO | NO |
CVE-2016-2779HIGH runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. | Feb 7, 2017 | 7.8 | 25 | NO | NO |
CVE-2026-27456MEDIUM util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mo | Apr 3, 2026 | 4.7 | 21 | NO | NO |
CVE-2021-3996MEDIUM A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vuln | Aug 23, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-3995MEDIUM A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local | Aug 23, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-0563MEDIUM A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the lib | Feb 21, 2022 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Util Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.27 | 1 | 9.8 | 4.5% | 0 | 0 |
| 2.24.2-1 | 1 | 7.8 | 0.4% | 0 | 0 |
| 2.17.2 | 1 | 2.1 | 0.4% | 0 | 0 |
| 2.14.1 | 1 | 2.1 | 0.4% | 0 | 0 |