upstream upgrade with security fixes: CVE-2026-53612 - libmount: TOCTOU attack via ancestor directory swap during mount CVE-2026-53613 - libmount: SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path ...
Metric names and values are now validated to ensure they do not contain characters below ASCII 32 (including newlines), colon (':') or pipe ('|') characters that might allow metric injection. Offending calls now croak.