mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 00:04:06 -09:00
351a42c6733a5174f5cef05a1cfe506a2bea3540
- CVE-2026-53612
A TOCTOU (Time-of-Check-Time-of-Use) vulnerability exists in the
SUID binary /usr/bin/mount from util-linux. The hook_owner.c
post-mount hook performs path-based chmod() and lchown() operations
on the mount target after mount() has completed, without verifying
that the target path still resolves to the same filesystem object.
An unprivileged local user can exploit this race window using
renameat2(RENAME_EXCHANGE) to redirect the chmod()/lchown() to an
arbitrary path, achieving arbitrary permission/ownership
modification on any file or directory.
For more information, see:
- https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh
- d0c5adaeb3
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
…
…
…
Buildroot is a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation. The documentation can be found in docs/manual. You can generate a text document with 'make manual-text' and read output/docs/manual/manual.text. Online documentation can be found at https://buildroot.org/docs.html To build and use the buildroot stuff, do the following: 1) run 'make menuconfig' 2) select the target architecture and the packages you wish to compile 3) run 'make' 4) wait while it compiles 5) find the kernel, bootloader, root filesystem, etc. in output/images You do not need to be root to build or run buildroot. Have fun! Buildroot comes with a basic configuration for a number of boards. Run 'make list-defconfigs' to view the list of provided configurations. Please feed suggestions, bug reports, insults, and bribes back to the buildroot mailing list: buildroot@buildroot.org You can also find us on #buildroot on OFTC IRC. If you would like to contribute patches, please read https://buildroot.org/manual.html#submitting-patches
Description
Languages
Makefile
62.5%
Python
19%
C
8.5%
Shell
6.1%
PHP
1.4%
Other
2.1%