CVE-2026-13595
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Published:
6/29/2026
Last updated:
6/30/2026
Reserved:
6/29/2026
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.
CNA assigner:
redhat (53f830b8-0a3f-465b-8143-3b8a9948e749)
Requested by:
n/a
Opam packages affected (1)
vhdlib
Products affected (12)
| Product |
Vendor |
Version |
| Red Hat OpenShift Container Platform 4 |
Red Hat
|
n/a
|
| Red Hat OpenShift Container Platform 4 |
Red Hat
|
< 24.0.26.136
|
| Red Hat Enterprise Linux 8 |
Red Hat
|
< 97.0.4692.71
|
| Red Hat Enterprise Linux 9 |
Red Hat
|
2.08B01
|
| Red Hat Hardened Images |
Red Hat
|
3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17
|
| Red Hat Enterprise Linux 10 |
Red Hat
|
< unspecified
|
| Red Hat Enterprise Linux 7 |
Red Hat
|
<= 6.2.1
|
| Red Hat Enterprise Linux 8 |
Red Hat
|
< 4.8.1
|
| Red Hat Enterprise Linux 9 |
Red Hat
|
< 4.8.1
|
| Red Hat Enterprise Linux 10 |
Red Hat
|
n/a
|
| Red Hat Enterprise Linux 7 |
Red Hat
|
n/a
|
| Red Hat Hardened Images |
Red Hat
|
< unspecified
|
Credits (2)
-
Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue.
-
Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue.