Missing Release of File Descriptor or Handle after Effective Lifetime Affecting util-linux package, versions <2.41.6-r1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.19% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE323-UTILLINUX-19533446
  • published5 Sept 2026
  • disclosed2 Sept 2026

Introduced: 2 Sep 2026

CVE-2026-78408  (opens in a new tab)
CWE-775  (opens in a new tab)

How to fix?

Upgrade Alpine:3.23 util-linux to version 2.41.6-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Alpine. See How to fix? for Alpine:3.23 relevant fixed versions and status.

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

CVSS Base Scores

version 3.1