REDHAT-BUG-2494101: Use After Free

Published Jun 29, 2026
·
Updated

A heap use-after-free vulnerability was found in libblkid's nested partition probing code in util-linux. The probebsdpt() function in libblkid/src/partitions/bsd.c caches a blkidpartition parent pointer into the partlist's heap-allocated parts[] array, then loops calling blkidpartlistaddpartition(), which may reallocarray() the same array. After reallocation, the stale parent pointer is dereferenced via blkidpartitiongetstart() — an 8-byte heap use-after-free read. The same dangling-pointer pattern exists in the minix, solarisx86, and unixware nested probers.

A crafted 2 MiB DOS/MBR disk image with three BSD-typed primaries (each holding >=16 slices) plus an md-raid 0.90 superblock triggers the issue via stock blkid -p. libblkid runs as root via udev/udisks on every block-device hot-plug event.

Upstream fix: https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c

Affected Software

1 affected component
util-linux util-linux libblkid

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade util-linux/libblkid to a version that resolves this vulnerability.

    Patch c0186f14fbdb02f64c8e0ba701ce727ea764ff4c
  2. Compensating control

    Reduce exposure by limiting blkid/libblkid execution on hot-plug block-device events (e.g., restrict udev/udisks-triggered probing to trusted devices or disable/limit udev rules that invoke util-linux libblkid for untrusted removable media).

Event History

Jun 29, 2026
Data Sourced
via Red Hat·07:41 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2494101?

The severity of REDHAT-BUG-2494101 is classified as medium (4).

2

What type of vulnerability is described in REDHAT-BUG-2494101?

REDHAT-BUG-2494101 describes a heap use-after-free vulnerability in libblkid's nested partition probing code.

3

How do I fix REDHAT-BUG-2494101?

To fix REDHAT-BUG-2494101, you need to update the util-linux package to the latest version that addresses this vulnerability.

4

Which software is affected by REDHAT-BUG-2494101?

The software affected by REDHAT-BUG-2494101 is util-linux and its libblkid library.

5

What functions are involved in the vulnerability described in REDHAT-BUG-2494101?

The probe_bsd_pt() function in libblkid/src/partitions/bsd.c is involved in the vulnerability described in REDHAT-BUG-2494101.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203