CVE-2026-13595

Publication date 29 June 2026

Last updated 31 August 2026


Ubuntu priority

Cvss 3 Severity Score

6.8 · Medium

Score breakdown

Description

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Status

Package Ubuntu Release Status
util-linux 26.04 LTS resolute
Fixed 2.41.3-3ubuntu2.2
25.10 questing Ignored end of life, was needs-triage
24.04 LTS noble
Fixed 2.39.3-9ubuntu6.6
22.04 LTS jammy
Fixed 2.37.2-4ubuntu3.6
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
util-linux

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.8 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H


Access our resources on patching vulnerabilities