Debian Security Advisory

DSA-4134-1 util-linux -- security update

Date Reported:
10 Mar 2018
Affected Packages:
util-linux
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 892179.
In Mitre's CVE dictionary: CVE-2018-7738.
More information:

Bjorn Bosselmann discovered that the umount bash completion from util-linux does not properly handle embedded shell commands in a mountpoint name. An attacker with rights to mount filesystems can take advantage of this flaw for privilege escalation if a user (in particular root) is tricked into using the umount completion while a specially crafted mount is present.

For the stable distribution (stretch), this problem has been fixed in version 2.29.2-1+deb9u1.

We recommend that you upgrade your util-linux packages.

For the detailed security status of util-linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/util-linux