Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
6.8
CVE-2026-13595EXPLOITEDPATCHED
red hat · hardened_images

Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

Description

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Affected Products

VendorProductVersions
red hathardened_images—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
kernelutil-linuxcve_cpe95%
open sourceopen source util-linuxcert_advisory90%
red hatopenshift_container_platformcve_cpe95%
red hatenterprise_linuxcve_cpe95%

References

  • https://access.redhat.com/errata/RHSA-2026:26573(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-13595(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2494101(issue-tracking, x_refsource_REDHAT)
  • https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c

Related News (8 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories47d ago
[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen ermöglichen Denial of Service
→ No new info (linked only)
Tier A
Microsoft MSRC53d ago
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
→ No new info (linked only)
Tier C
VulDB55d ago
CVE-2026-13595 | Red Hat libblkid use after free
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[NEU] [mittel] util-linux: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[UPDATE] [hoch] Red Hat Enterprise Linux: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[UPDATE] [hoch] Red Hat Enterprise Linux: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories117d ago
[UPDATE] [hoch] Red Hat Produkte: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.16.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.42.2-1.hum1
CWECWE-416
PublishedJun 29, 2026
Last enriched55d agov2
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilitiesCVE-2026-13595
Trending Score36
Source articles8
Independent4
Info Completeness8/14
Missing: versions, epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-18917EXP
Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
Trending: 35
NONECVE-2026-17523EXP
Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
Trending: 33
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 26
MEDIUMCVE-2026-73199EXP
Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
Trending: 23
NONECVE-2026-77176
Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 29, 2026
Discovered by ZDM
Jun 29, 2026
Updated: description, severity, tags
Jun 29, 2026
Actively Exploited
Aug 21, 2026
Exploit Available
Aug 21, 2026
Patch Available
Aug 21, 2026

Version History

v2
Last enriched 55d ago
v2Tier C55d ago

Updated severity to CRITICAL, changed vendor and product to Red Hat and libblkid, and added new description and CVE ID.

descriptionseveritytags
via VulDB
v155d ago

Initial creation