CVE-2015-5224: Kernel Util-Linux

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.

Affected products

  • Kernel Util-Linux: up to and including 2.26.2; version 2.27 only

Published 2017-08-23. Last modified 2026-06-17.