CVE-2026-78409 vulnerability in Red Hat Products
Published on September 2, 2026
Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
Vulnerability Analysis
CVE-2026-78409 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-78409. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public. 77 days later.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-78409 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-78409
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.