openSUSE 16: lastlog2 / libblkid-devel / libblkid-devel-static / libblkid1 / etc (openSUSE-SU-2026:21905-1)

high Nessus Plugin ID 350149

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21905-1 advisory.

- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347).

Changes for util-linux:

- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1261606

https://bugzilla.suse.com/1268886

https://bugzilla.suse.com/1269583

https://bugzilla.suse.com/1270219

https://bugzilla.suse.com/1275441

https://bugzilla.suse.com/1278347

https://bugzilla.suse.com/1278348

https://bugzilla.suse.com/1278349

https://www.suse.com/security/cve/CVE-2026-13595

https://www.suse.com/security/cve/CVE-2026-27456

https://www.suse.com/security/cve/CVE-2026-53612

https://www.suse.com/security/cve/CVE-2026-53613

https://www.suse.com/security/cve/CVE-2026-53614

https://www.suse.com/security/cve/CVE-2026-76642

https://www.suse.com/security/cve/CVE-2026-78408

https://www.suse.com/security/cve/CVE-2026-78410

Plugin Details

Severity: High

ID: 350149

File Name: openSUSE-2026-21905-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.5

Percentile: 98.29

CVSS v2

Risk Factor: Medium

Base Score: 4.5

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:N/A:C

CVSS Score Source: CVE-2026-13595

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.5

Threat Score: 7.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-76642

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:lastlog2, p-cpe:/a:novell:opensuse:libblkid-devel-static, p-cpe:/a:novell:opensuse:libblkid-devel, p-cpe:/a:novell:opensuse:libblkid1, p-cpe:/a:novell:opensuse:libfdisk-devel-static, p-cpe:/a:novell:opensuse:libfdisk-devel, p-cpe:/a:novell:opensuse:libfdisk1, p-cpe:/a:novell:opensuse:liblastlog2-2, p-cpe:/a:novell:opensuse:liblastlog2-devel, p-cpe:/a:novell:opensuse:libmount-devel-static, p-cpe:/a:novell:opensuse:libmount-devel, p-cpe:/a:novell:opensuse:libmount1, p-cpe:/a:novell:opensuse:libsmartcols-devel-static, p-cpe:/a:novell:opensuse:libsmartcols-devel, p-cpe:/a:novell:opensuse:libsmartcols1, p-cpe:/a:novell:opensuse:libuuid-devel-static, p-cpe:/a:novell:opensuse:libuuid-devel, p-cpe:/a:novell:opensuse:libuuid1, p-cpe:/a:novell:opensuse:python313-libmount, p-cpe:/a:novell:opensuse:util-linux-extra, p-cpe:/a:novell:opensuse:util-linux-lang, p-cpe:/a:novell:opensuse:util-linux-systemd, p-cpe:/a:novell:opensuse:util-linux-tty-tools, p-cpe:/a:novell:opensuse:util-linux, p-cpe:/a:novell:opensuse:uuidd

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 4/1/2026

Reference Information

CVE: CVE-2026-13595, CVE-2026-27456, CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408, CVE-2026-78410

IAVA: 2026-A-0384