Skip to content
Red HatCVE-2026-78409

Red Hat Enterprise Linux 10: link following

High7.0CVE-2026-78409 · Published Sep 2, 2026 · updated Sep 3, 2026

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution
Critical9.1Sep 2
Red Hat rpm: command injection
High7.8Sep 2
Red Hat Enterprise Linux 10: command injection
High7.8Sep 2
The nsenter --join-cgroup option opens the target cgroup.procs file as root and...
High7.9Sep 2
Red Hat util-linux: race condition
High7.8Sep 2
Red Hat Enterprise Linux: open redirect
Medium4.3Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.