{"id":"ECHO-3eb2-a6d4-7b02","upstream":["CVE-2026-78409"],"severity":[],"modified":"2026-09-06T09:15:09.413Z","affected":[{"package":{"ecosystem":"Echo","name":"util-linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41.5-0+deb13u1+e2"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-78409"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-78409"}],"withdrawn":"2026-09-06T09:15:09.413Z","summary":"The detached-tree X-mount.subdir path arrived in 2.42 (ae19f7546); our libmount\nhas no AT_SYMLINK_NOFOLLOW, no api->subdir in hook_mount.c and no 6.15 logic.\nUpstream shipped 2.41.6 the same day as 2.42.3 with the other three CVEs and\ndeliberately not this one. Debian marks trixie vulnerable but also bookworm\n2.38.1, which predates the path entirely.\nhttps://security-tracker.debian.org/tracker/CVE-2026-78409\n"}