@@ -49,6 +49,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
file://CVE-2026-27456.patch \
file://CVE-2026-13595.patch \
file://CVE-2026-3184.patch \
+ file://CVE-2026-53614.patch \
"
SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f"
new file mode 100644
@@ -0,0 +1,83 @@
+From cc81bbcec598cb91f0eb8456282f33eed820ed5f Mon Sep 17 00:00:00 2001
+From: Karel Zak <kzak@redhat.com>
+Date: Tue, 16 Jun 2026 10:58:32 +0200
+Subject: [PATCH] libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and
+ legacy mount path
+
+Use safe_getenv() for LIBMOUNT_FORCE_MOUNT2 to ignore the variable
+in SUID context, consistent with LIBMOUNT_FSTAB and other sensitive
+environment variables.
+
+Additionally, refuse multi-step mount(2) sequences (bind+remount and
+propagation) for restricted (non-root) users in the legacy mount path.
+The two-step approach has a window between syscalls where security
+flags (nosuid, noexec, ...) are not yet applied. The new mount API
+handles this atomically.
+
+CVE-2026-53614
+
+Reported-by: Xinyao Hu <ctf_0x01@foxmail.com>
+Signed-off-by: Karel Zak <kzak@redhat.com>
+(cherry picked from commit 9cbfb823500f510b34767edabd3ffd5b436987b4)
+
+CVE: CVE-2026-53614
+Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/cc81bbcec598cb91f0eb8456282f33eed820ed5f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libmount/src/hook_mount.c | 3 ++-
+ libmount/src/hook_mount_legacy.c | 8 ++++++++
+ 2 files changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/libmount/src/hook_mount.c b/libmount/src/hook_mount.c
+index 1ffd19e83..37179fb59 100644
+--- a/libmount/src/hook_mount.c
++++ b/libmount/src/hook_mount.c
+@@ -44,6 +44,7 @@
+ */
+
+ #include "mountP.h"
++#include "env.h"
+ #include "fileutils.h" /* statx() fallback */
+ #include "strutils.h"
+ #include "mount-api-utils.h"
+@@ -627,7 +628,7 @@ fail:
+
+ static int force_classic_mount(struct libmnt_context *cxt)
+ {
+- const char *env = getenv("LIBMOUNT_FORCE_MOUNT2");
++ const char *env = safe_getenv("LIBMOUNT_FORCE_MOUNT2");
+
+ if (env) {
+ if (strcmp(env, "always") == 0)
+diff --git a/libmount/src/hook_mount_legacy.c b/libmount/src/hook_mount_legacy.c
+index 18b7a0066..94a8fc685 100644
+--- a/libmount/src/hook_mount_legacy.c
++++ b/libmount/src/hook_mount_legacy.c
+@@ -282,6 +282,8 @@ static int hook_prepare(struct libmnt_context *cxt,
+
+ /* add extra mount(2) calls for each propagation flag */
+ if (flags & MS_PROPAGATION) {
++ if (mnt_context_is_restricted(cxt))
++ goto eperm;
+ rc = prepare_propagation(cxt, hs);
+ if (rc)
+ return rc;
+@@ -291,12 +293,18 @@ static int hook_prepare(struct libmnt_context *cxt,
+ if ((flags & MS_BIND)
+ && (flags & MNT_BIND_SETTABLE)
+ && !(flags & MS_REMOUNT)) {
++ if (mnt_context_is_restricted(cxt))
++ goto eperm;
+ rc = prepare_bindremount(cxt, hs);
+ if (rc)
+ return rc;
+ }
+
+ return rc;
++eperm:
++ DBG(HOOK, ul_debugobj(hs,
++ "multi-step mount(2) refused for non-root user"));
++ return -EPERM;
+ }
+
+ const struct libmnt_hookset hookset_mount_legacy =