This bug was fixed in the package util-linux - 2.42.2-1ubuntu2
---------------
util-linux (2.42.2-1ubuntu2) stonking; urgency=medium
* d/p/ubuntu/libmount-restricted-live-creds.patch: restore live-credential
check for libmount restricted mode (LP: #2166882)
util-linux (2.42.2-1ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2153369).
Added changes:
- tests/fincore: force the use of GNU dd over uutils (LP: #2125968)
Remaining changes:
- Add sulogin-fallback-static-sh.patch
Add support for /bin/static-sh as fallback if the regular shell fails to
execute. Patch ported from sysvinit. (see LP #505887)
- Add sulogin-lockedpwd.patch
Make sure file systems can be fixed on machines with locked root
accounts (as Ubuntu does by default). Don't require --force for sulogin.
- d/rules: disable libmount mountfs support
Disable brand new feature with --disable-libmount-mountfd-support that
causes inability to deploy MAAS LP #2037417.
- d/p/ubuntu/su-pty-drop-caps.patch: harden 'su --pty' to temporarily lower
capabilities while proxying between stdin/stdout and the pty master. This
is to avoid su from being used to exploit kernel vulnerabilities.
util-linux (2.42.2-1) unstable; urgency=medium
* New upstream version, fixing security issues
CVE-2026-53612, CVE-2026-53613, CVE-2026-53614 (Closes: #1140194,
#1140195, #1140196)
* Drop upstream-applied patch.
util-linux (2.42.1-6) unstable; urgency=medium
* Follow debhelper 14.1, thus putting PAM files back into /etc/pam.d.
Note that include=login is still undesirable, and packages should
include common-* instead.
util-linux (2.42.1-5) unstable; urgency=medium
* PAM config: stop using include.
Avoid including our own PAM config files, as a workaround until PAM can
include files from /usr/lib/pam.d.
Should make su -(l) and runuser -l work again. See #1140029.
util-linux (2.42.1-4) unstable; urgency=medium
* Update debhelper-compat to v14.
Remove dh-sequence-installsysusers, remove ${misc:Pre-Depends} from
Pre-Depends. PAM /etc/pam.d files are replaced by files in
/usr/lib/pam.d.
util-linux (2.42.1-3) unstable; urgency=medium
* Use upstream patch to fix FTBFS on systems with non-4K pagesizes
(Closes: #1138789)
util-linux (2.42.1-2) unstable; urgency=medium
* Fix FTBFS on systems with non-4K pagesizes (Closes: #1138789)
util-linux (2.42.1-1) unstable; urgency=medium
* New upstream version
* Refresh/drop upstream applied patches
[ Karel Zak ]
* script: fix backward compatibility for options after non-option args
* script: fix "--" separator when used as option argument
(Closes: #1132887)
util-linux (2.42-6) unstable; urgency=medium
* Stop using Linux crypto API in hardlink(1)
util-linux (2.42-5) unstable; urgency=medium
* Remove leftover /etc/init.d/uuidd conffile
util-linux (2.42-4) unstable; urgency=medium
* Apply upstream revert of su breakage
(Closes: #1133379, #1132588, #1132610)
util-linux (2.42-3) unstable; urgency=medium
* Stop pulling deb_systemdsystemunitdir from pkg-config
* Stop installing uuidd init script
* Clarify /bin/login situation on Hurd
* Install bash-completions using normal dh_install mechanism
* Install more localized man pages
* Simplify installing into udebs
* Install lintian overrides into udebs
* Run a second build without libsystemd for d-i.
This is not great, but I see no other option at this time.
Let's hope a libsystemd0-udeb will appear. (Closes: #1132561)
* util-linux-extra: install copyfilerange, getino
* Update lintian overrides
* Update dependency libselinux1-dev to libselinux-dev
util-linux (2.42-2) unstable; urgency=medium
* Add upstream patches addressing #1132887
util-linux (2.42-1) unstable; urgency=medium
* New upstream release, fixing CVE-2026-27456 and a CWE-190.
* Upload to unstable.
util-linux (2.42~rc2-1) experimental; urgency=medium
* New upstream release candidate.
* Refresh patches
util-linux (2.42~rc1-3) experimental; urgency=medium
* Apply upstream patches
* Fixes unshare issue
* Use Hurd patches directly from upstream
util-linux (2.42~rc1-2) experimental; urgency=medium
* Fix lsmem tests on loong64.
Using patch from https://github.com/util-linux/util-linux/pull/4090
* autopkgtests: switch to pkgconf
[ Samuel Thibault ]
* Fix build on Hurd
util-linux (2.42~rc1-1) experimental; urgency=medium
* New upstream release candidate.
* includes fix for CVE-2026-3184:
* login: use original FQDN for PAM_RHOST
* libuuid: reset initial cont-clock time on service start (Closes:
#1126894)
* Symbols: use (symver) and update lists
* Stop installing untranslated man pages
util-linux (2.41.3-4) unstable; urgency=medium
[ Chris Hofstaedtler ]
* Follow libselinux1-dev to libselinux-dev rename (Closes: #1124751)
* uuid-runtime: stop removing /var/run/uuidd on purge
/run is a tmpfs, it will be cleaned up anyway. Lets us drop the postrm
maintscript.
[ Luca Boccassi ]
* uuid-runtime: drop manual scripting in postinst and rely on sysusers.d
-- Nadzeya Hutsko <[email protected]> Wed, 16 Sep 2026 19:36:33 +0200
** Changed in: util-linux (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-27456
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3184
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53612
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53613
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53614
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153369
Title:
Merge util-linux from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/util-linux/+bug/2153369/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs