Util Linux

Vendor:

First CVE: Dec 31, 2001 · Active for 24 years

18
Total CVEs
More Total CVEs than 93% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Util Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

CVE Severity & Scoring

Util Linux18 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local12 (66.7%)
Network2 (11.1%)
Unknown3 (16.7%)
Physical1 (5.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (77.8%)
High1 (5.6%)
Unknown3 (16.7%)
User Interaction
None14 (77.8%)
Unknown3 (16.7%)
Required1 (5.6%)
Privileges Required
Low9 (50.0%)
High1 (5.6%)
None5 (27.8%)
Unknown3 (16.7%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent
Jun 29, 20266.834NONO
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount co
Mar 7, 20187.826NONO
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
Mar 31, 20177.826NONO
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before sett
Apr 3, 20265.325NONO
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
Aug 23, 20179.825NONO
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Feb 7, 20177.825NONO
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mo
Apr 3, 20264.721NONO
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vuln
Aug 23, 20225.521NONO
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local
Aug 23, 20225.521NONO
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the lib
Feb 21, 20225.521NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Util Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2719.84.5%00
2.24.2-117.80.4%00
2.17.212.10.4%00
2.14.112.10.4%00