Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21905-1 advisory.
- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347).
Changes for util-linux:
- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219).
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: openSUSE-2026-21905-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:N/A:C
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:lastlog2, p-cpe:/a:novell:opensuse:libblkid-devel-static, p-cpe:/a:novell:opensuse:libblkid-devel, p-cpe:/a:novell:opensuse:libblkid1, p-cpe:/a:novell:opensuse:libfdisk-devel-static, p-cpe:/a:novell:opensuse:libfdisk-devel, p-cpe:/a:novell:opensuse:libfdisk1, p-cpe:/a:novell:opensuse:liblastlog2-2, p-cpe:/a:novell:opensuse:liblastlog2-devel, p-cpe:/a:novell:opensuse:libmount-devel-static, p-cpe:/a:novell:opensuse:libmount-devel, p-cpe:/a:novell:opensuse:libmount1, p-cpe:/a:novell:opensuse:libsmartcols-devel-static, p-cpe:/a:novell:opensuse:libsmartcols-devel, p-cpe:/a:novell:opensuse:libsmartcols1, p-cpe:/a:novell:opensuse:libuuid-devel-static, p-cpe:/a:novell:opensuse:libuuid-devel, p-cpe:/a:novell:opensuse:libuuid1, p-cpe:/a:novell:opensuse:python313-libmount, p-cpe:/a:novell:opensuse:util-linux-extra, p-cpe:/a:novell:opensuse:util-linux-lang, p-cpe:/a:novell:opensuse:util-linux-systemd, p-cpe:/a:novell:opensuse:util-linux-tty-tools, p-cpe:/a:novell:opensuse:util-linux, p-cpe:/a:novell:opensuse:uuidd
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 9/22/2026
Vulnerability Publication Date: 4/1/2026