Use-After-Free Vulnerability in Util-Linux's Libblkid Library
CVE-2026-13595
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 29 June 2026
What is CVE-2026-13595?
A vulnerability has been identified in the libblkid library of util-linux that allows for a use-after-free condition. This occurs during nested partition probing where a stale pointer to a parent partition entry is cached in a dynamically allocated array. If subsequent partition modifications lead to the reallocation of this array, attackers can exploit this flaw without user interaction. By presenting a specially crafted block device image, possibly through USB or loop-mounted disk images, attackers can trigger issues that may result in limited information disclosure or denial of service, as libblkid is called automatically by udev/udisks during block-device hot-plug events.
Affected Version(s)
Red Hat Hardened Images 2.42.2-1.hum1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved