diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc
index f651dc2dab4..70acf6dfec3 100644
--- a/meta/recipes-core/util-linux/util-linux.inc
+++ b/meta/recipes-core/util-linux/util-linux.inc
@@ -49,6 +49,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
            file://CVE-2026-27456.patch \
            file://CVE-2026-13595.patch \
            file://CVE-2026-3184.patch \
+           file://CVE-2026-53614.patch \
            "
 
 SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f"
diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-53614.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-53614.patch
new file mode 100644
index 00000000000..f1dd4ae5d74
--- /dev/null
+++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-53614.patch
@@ -0,0 +1,83 @@
+From cc81bbcec598cb91f0eb8456282f33eed820ed5f Mon Sep 17 00:00:00 2001
+From: Karel Zak <kzak@redhat.com>
+Date: Tue, 16 Jun 2026 10:58:32 +0200
+Subject: [PATCH] libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and
+ legacy mount path
+
+Use safe_getenv() for LIBMOUNT_FORCE_MOUNT2 to ignore the variable
+in SUID context, consistent with LIBMOUNT_FSTAB and other sensitive
+environment variables.
+
+Additionally, refuse multi-step mount(2) sequences (bind+remount and
+propagation) for restricted (non-root) users in the legacy mount path.
+The two-step approach has a window between syscalls where security
+flags (nosuid, noexec, ...) are not yet applied.  The new mount API
+handles this atomically.
+
+CVE-2026-53614
+
+Reported-by: Xinyao Hu <ctf_0x01@foxmail.com>
+Signed-off-by: Karel Zak <kzak@redhat.com>
+(cherry picked from commit 9cbfb823500f510b34767edabd3ffd5b436987b4)
+
+CVE: CVE-2026-53614
+Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/cc81bbcec598cb91f0eb8456282f33eed820ed5f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libmount/src/hook_mount.c        | 3 ++-
+ libmount/src/hook_mount_legacy.c | 8 ++++++++
+ 2 files changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/libmount/src/hook_mount.c b/libmount/src/hook_mount.c
+index 1ffd19e83..37179fb59 100644
+--- a/libmount/src/hook_mount.c
++++ b/libmount/src/hook_mount.c
+@@ -44,6 +44,7 @@
+  */
+ 
+ #include "mountP.h"
++#include "env.h"
+ #include "fileutils.h"	/* statx() fallback */
+ #include "strutils.h"
+ #include "mount-api-utils.h"
+@@ -627,7 +628,7 @@ fail:
+ 
+ static int force_classic_mount(struct libmnt_context *cxt)
+ {
+-	const char *env = getenv("LIBMOUNT_FORCE_MOUNT2");
++	const char *env = safe_getenv("LIBMOUNT_FORCE_MOUNT2");
+ 
+ 	if (env) {
+ 		if (strcmp(env, "always") == 0)
+diff --git a/libmount/src/hook_mount_legacy.c b/libmount/src/hook_mount_legacy.c
+index 18b7a0066..94a8fc685 100644
+--- a/libmount/src/hook_mount_legacy.c
++++ b/libmount/src/hook_mount_legacy.c
+@@ -282,6 +282,8 @@ static int hook_prepare(struct libmnt_context *cxt,
+ 
+ 	/* add extra mount(2) calls for each propagation flag  */
+ 	if (flags & MS_PROPAGATION) {
++		if (mnt_context_is_restricted(cxt))
++			goto eperm;
+ 		rc = prepare_propagation(cxt, hs);
+ 		if (rc)
+ 			return rc;
+@@ -291,12 +293,18 @@ static int hook_prepare(struct libmnt_context *cxt,
+ 	if ((flags & MS_BIND)
+ 	    && (flags & MNT_BIND_SETTABLE)
+ 	    && !(flags & MS_REMOUNT)) {
++		if (mnt_context_is_restricted(cxt))
++			goto eperm;
+ 		rc = prepare_bindremount(cxt, hs);
+ 		if (rc)
+ 			return rc;
+ 	}
+ 
+ 	return rc;
++eperm:
++	DBG(HOOK, ul_debugobj(hs,
++		"multi-step mount(2) refused for non-root user"));
++	return -EPERM;
+ }
+ 
+ const struct libmnt_hookset hookset_mount_legacy =
