Security: uutils/coreutils
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
`install` fd-based copy path creates the destination `0666` and without `O_EXCL`GHSA-54x6-c4c8-44fr published
Sep 17, 2026 by sylvestreModerate -
stdbuf: world-writable LD_PRELOAD temporary directory allows local code execution; temp directories are also leakedGHSA-939x-8rj3-7p25 published
Sep 5, 2026 by sylvestreHigh -
cp -a chmods through an attacker-swapped destination symlink in copy_extended_attrs (TOCTOU) — an unprivileged user makes an arbitrary root-owned file world-writableGHSA-8r5f-98ww-c4c5 published
Sep 5, 2026 by sylvestreHigh -
chmod: `--reference` combined with `-R` dereferences symlinks encountered during recursion, allowing arbitrary file permission modification (local privilege escalation)GHSA-pqxf-vf75-qfxj published
Sep 5, 2026 by sylvestreHigh -
install --backup has no source-is-backup guard and silently destroys the sourceGHSA-x2p7-fq8x-g67j published
Aug 7, 2026 by sylvestreLow -
`mv --backup=simple` safety guard fails open when operands are spelled differently, silently destroying the sourceGHSA-mcrj-cqrc-m6rh published
Aug 7, 2026 by sylvestreLow -
install can leave a root-owned setuid artifact when ownership finalization failsGHSA-cgg3-923w-v53m published
Sep 16, 2026 by sylvestreModerate -
rm -r: top-level operand can be raced before fd-based traversal (TOCTOU)GHSA-9gw8-m5cj-3cr6 published
Sep 5, 2026 by sylvestreHigh -
kill: -<N> kills the target processGHSA-3jmh-xh36-pj6v published
Aug 7, 2026 by sylvestreLow -
uutils mv cross-device fallback retains setuid/setgid bits when ownership cannot be preservedGHSA-6c4j-6pgg-xgg8 published
Sep 13, 2026 by sylvestreLow