CVE-2026-13595: Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

Published Jun 29, 2026
·
Updated

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Other sources

A heap use-after-free vulnerability was found in libblkid's nested partition probing code in util-linux. The probebsdpt() function in libblkid/src/partitions/bsd.c caches a blkidpartition parent pointer into the partlist's heap-allocated parts[] array, then loops calling blkidpartlistaddpartition(), which may reallocarray() the same array. After reallocation, the stale parent pointer is dereferenced via blkidpartitiongetstart() — an 8-byte heap use-after-free read. The same dangling-pointer pattern exists in the minix, solarisx86, and unixware nested probers.

A crafted 2 MiB DOS/MBR disk image with three BSD-typed primaries (each holding >=16 slices) plus an md-raid 0.90 superblock triggers the issue via stock blkid -p. libblkid runs as root via udev/udisks on every block-device hot-plug event.

Upstream fix: https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c

Red Hat

Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

Microsoft

Affected Software

11 affected componentsFixes available
util-linux libblkid
util-linux util-linux
Microsoft azl3 util-linux 2.40.2-4<2.40.2-5
2.40.2-5
Microsoft azl3 util-linux 2.40.2-5<2.40.2-5
2.40.2-5
redhat Hardened Images
redhat OpenShift Container Platform>=4.0<=4.22.1
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
kernel util-linux<2.42.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.40.2-5
  2. Upgrade

    Upgrade util-linux (libblkid) to a version that resolves this vulnerability.

    Patch c0186f14fbdb02f64c8e0ba701ce727ea764ff4c
  3. Compensating control

    Mitigate exploitability by preventing untrusted block-device images from being hot-plugged/added to systems that run udev/udisks calling libblkid as root (e.g., restrict allowed USB/block device sources or disable/block the udev/udisks hot-plug paths for untrusted devices).

Event History

Jun 29, 2026
Data Sourced
via Red Hat·07:41 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 1, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
Affected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13595?

CVE-2026-13595 has a medium severity score of 6.8.

2

What vulnerability type is CVE-2026-13595 associated with?

CVE-2026-13595 is associated with the Use After Free vulnerability type.

3

How do I fix CVE-2026-13595?

To mitigate CVE-2026-13595, update util-linux to the latest version that addresses this vulnerability.

4

What systems are affected by CVE-2026-13595?

CVE-2026-13595 affects systems using the libblkid library in util-linux, particularly those utilizing BSD, Minix, Solaris x86, and UnixWare partition probers.

5

What impact does CVE-2026-13595 have?

The impact of CVE-2026-13595 includes a potential denial of service due to a heap use-after-free condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203