Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package util-linux for openSUSE:Factory 
checked in at 2026-09-23 14:32:04
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/util-linux (Old)
 and      /work/SRC/openSUSE:Factory/.util-linux.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "util-linux"

Wed Sep 23 14:32:04 2026 rev:313 rq:1379325 version:2.42.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/util-linux/util-linux.changes    2026-08-20 
16:13:54.808312781 +0200
+++ /work/SRC/openSUSE:Factory/.util-linux.new.383539/util-linux.changes        
2026-09-23 14:32:06.357201795 +0200
@@ -1,0 +2,78 @@
+Sun Sep 20 16:29:05 UTC 2026 - Stanislav Brabec <[email protected]>
+
+- Update to version 2.42.3:
+  * Security fixes:
+    * CVE-2026-76642 - mount(8) post-mount hooks execute after
+      helper failure.
+      When an external mount.<type> helper exits nonzero,
+      post-mount hooks (X-mount.idmap, X-mount.owner/group/mode)
+      still execute as if the mount had succeeded, allowing
+      privileged operations on the pre-existing target filesystem
+      (bsc#1274864, bsc#1278349).
+    * CVE-2026-78410 - mount(8) TOCTOU race on source path.
+      In restricted (SUID, non-root) mode, the source path is
+      canonicalized with realpath() as euid=0, following symlinks
+      through user-writable directories.  Additionally, open_tree()
+      follows symlinks in intermediate path components.  A local
+      attacker can redirect a privileged mount or post-mount
+      ownership change to an arbitrary path (bsc#1274864,
+      bsc#1278347).
+    * CVE-2026-78409 - mount(8) X-mount.subdir symlink escape.
+      The open_tree() call used to open a subdirectory on a
+      detached mount follows symlinks in intermediate path
+      components, allowing escape from the detached tree
+      (bsc#1274864, bsc#1278346).
+    * CVE-2026-78408 - nsenter(1), unshare(1) file descriptor leak.
+      File descriptors in nsenter and unshare were not created with
+      O_CLOEXEC, potentially leaking them across exec.  Added
+      O_CLOEXEC as defense in depth (bsc#1274864, bsc#1278348).
+ * wall(1), write(1) - hostname escape sequence injection.
+   The CVE-2024-28085 fix sanitized only message bodies; the banner
+   headers still interpolated the system hostname without
+   sanitization. An unprivileged user can inject terminal escape
+   sequences via a user namespace hostname.
+   Additional fix for CVE-2024-28085.
+   Reported-by: Skyler Ferrante
+  * agetty: fix spurious issue file reprinting on reload
+  * col:
+    * guard c_width sign before size_t cast in BS branch
+    * fix cur_col underflow on backspace over a wide char
+  * disk-utils: fix memory leak in execute function
+  * hexdump: stop after stdout write errors
+  * libblkid:
+    * befs fix possible load of misaligned address
+    * befs fix possible too large shift
+    * dos fix 32-bit overflow in partition start/size [coverity
+      CID 503517, 503518]
+    * (iso9660) fix out-of-bounds read of root dir record
+  * libfdisk: fix OOM on GPT with huge partition entries array
+  * libmount:
+    * skip post-mount hooks after failed mount helper
+      [CVE-2026-76642]
+    * pin source path with openat2() for restricted users
+      [CVE-2026-78410]
+    * restrict source path canonicalization for non-root users
+      [CVE-2026-78410]
+    * fix X-mount.subdir symlink following on detached tree
+      [CVE-2026-78409]
+    * reuse existing act fd in mnt_update_start on ro retry
+    * properly end act file in mnt_free_update
+    * don't ignore "/" target in mount --all when target
+      prefix is set
+  * lscpu:
+    * remove mmu reference not available in stable/v2.42
+    * add NULL guards for RISC-V ISA functions [coverity
+      CID 503785]
+  * mbsalign: check remaining buffer space before writing
+    hex escapes
+  * more: fix out-of-bounds write in get_line() on invalid
+    multibyte input
+  * nsenter, unshare: add O_CLOEXEC to all open() calls
+    [CVE-2026-78408]
+  * pg: fix out-of-bounds access past wbuf on a trailing tab
+  * unshare: Fix --map-auto regression
+  * wall, write: sanitize hostname in banner header
+- Refresh
+  Add-documentation-on-blacklisted-modules-to-mount-8-.patch.
+
+-------------------------------------------------------------------
@@ -19 +97 @@
-- Update to version 2.42.2:
+- Update to version 2.42.2 (PED-16740):
@@ -77 +155 @@
-- If needed, display post installation message.
+- If needed, display post installation message (bsc#1268886#c17).

Old:
----
  util-linux-2.42.2.tar.sign
  util-linux-2.42.2.tar.xz

New:
----
  util-linux-2.42.3.tar.sign
  util-linux-2.42.3.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ util-linux.spec ++++++
--- /var/tmp/diff_new_pack.fjaIol/_old  2026-09-23 14:32:07.733259321 +0200
+++ /var/tmp/diff_new_pack.fjaIol/_new  2026-09-23 14:32:07.735259405 +0200
@@ -85,7 +85,7 @@
 %endif
 # ulbuild == python
 
-Version:        2.42.2
+Version:        2.42.3
 Release:        0
 License:        GPL-2.0-or-later
 #Git-Clone:     https://github.com/util-linux/util-linux

++++++ Add-documentation-on-blacklisted-modules-to-mount-8-.patch ++++++
--- /var/tmp/diff_new_pack.fjaIol/_old  2026-09-23 14:32:07.759260408 +0200
+++ /var/tmp/diff_new_pack.fjaIol/_new  2026-09-23 14:32:07.764260617 +0200
@@ -8,14 +8,14 @@
  sys-utils/mount.8 |   28 +++++++++++++++++++++++++++-
  1 file changed, 27 insertions(+), 1 deletion(-)
 
-Index: util-linux-2.42.2/sys-utils/mount.8
+Index: util-linux-2.42.3/sys-utils/mount.8
 ===================================================================
---- util-linux-2.42.2.orig/sys-utils/mount.8
-+++ util-linux-2.42.2/sys-utils/mount.8
-@@ -219,6 +219,32 @@ The \fBuser\fP mount option is accepted
- When using the legacy \fBmount\fP(2) syscall (on older kernels without the 
new mount API), the mount target path is resolved by the kernel at syscall 
time. This means there is an inherent time\-of\-check\-to\-time\-of\-use 
(TOCTOU) window between the permission verification and the actual mount 
operation. If an ancestor directory of the mount target is writable by the 
unprivileged user, a path component could be swapped to redirect the mount to 
an unintended location. The new mount API (available since Linux 5.2) 
eliminates this issue by using file\-descriptor\-based target resolution. 
Administrators should ensure that mount target paths for \fBuser\fP mounts do 
not traverse directories writable by unprivileged users.
- .sp .5v
- .RE
+--- util-linux-2.42.3.orig/sys-utils/mount.8
++++ util-linux-2.42.3/sys-utils/mount.8
+@@ -223,6 +223,32 @@ When using the legacy \fBmount\fP(2) sys
+ For mount source paths, \fBmount\fP(8) only canonicalizes (resolves symlinks) 
paths starting with \fI/dev/\fP for unprivileged users and verifies the result 
stays within \fI/dev/\fP. Source paths outside \fI/dev/\fP (e.g. disk images in 
user\-writable directories) are kept as\-is from \fIfstab\fP.
+ .sp
+ Filesystem type auto\-detection for unprivileged users relies exclusively on 
\fBudev\fP metadata rather than direct device probing; this means file images 
that are not registered with udev require an explicit filesystem type in 
\fIfstab\fP.
 +.SS Blacklisted file systems
 +In the Linux kernel, file system types are implemented as kernel
 +modules. While many of these file systems are well maintained,
@@ -45,7 +45,7 @@
  .SS "Bind mount operation"
  .sp
  Remount part of the file hierarchy somewhere else. The call is:
-@@ -2772,4 +2798,4 @@ For bug reports, use the \c
+@@ -2778,4 +2804,4 @@ For bug reports, use the \c
  .SH "AVAILABILITY"
  .sp
  The \fBmount\fP command is part of the util\-linux package which can be 
downloaded from \c

++++++ util-linux-2.42.2.tar.xz -> util-linux-2.42.3.tar.xz ++++++
/work/SRC/openSUSE:Factory/util-linux/util-linux-2.42.2.tar.xz 
/work/SRC/openSUSE:Factory/.util-linux.new.383539/util-linux-2.42.3.tar.xz 
differ: char 15, line 1

Reply via email to