EulerOS Virtualization 2.12.1 (EulerOS-SA-2026-2764)

medium Nessus Plugin ID 328517

Synopsis

The remote EulerOS Virtualization host is missing a security update.

Description

According to the versions of the packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities :

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check- Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.(CVE-2026-27456)

Tenable has extracted the preceding description block directly from the EulerOS Virtualization security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected remote EulerOS Virtualization host.

See Also

http://www.nessus.org/u?c1b05234

Plugin Details

Severity: Medium

ID: 328517

File Name: EulerOS_SA-2026-2764.nasl

Version: 1.1

Type: Local

Published: 7/21/2026

Updated: 7/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6

Percentile: 96.69

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 3

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-27456

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.2

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:uvp:2.12.1, p-cpe:/a:huawei:euleros:libblkid, p-cpe:/a:huawei:euleros:libfdisk, p-cpe:/a:huawei:euleros:libmount, p-cpe:/a:huawei:euleros:libsmartcols, p-cpe:/a:huawei:euleros:libuuid, p-cpe:/a:huawei:euleros:util-linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 4/1/2026

Reference Information

CVE: CVE-2026-27456