USN-8091-1: util-linux vulnerability

Publication date

12 March 2026

Overview

util-linux could be made to run programs as an administrator.


Packages

Details

It was discovered that the util-linux su utility did not drop capabilities
when being used with the --pty option. While not a security issue by
itself, a local attacker could possibly use the su tool to exploit
vulnerabilities in other applications.

It was discovered that the util-linux su utility did not drop capabilities
when being used with the --pty option. While not a security issue by
itself, a local attacker could possibly use the su tool to exploit
vulnerabilities in other applications.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
25.10 questing util-linux –  2.41-4ubuntu4.2
24.04 LTS noble util-linux –  2.39.3-9ubuntu6.5
22.04 LTS jammy util-linux –  2.37.2-4ubuntu3.5
20.04 LTS focal util-linux –  2.34-0.1ubuntu9.6+esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›