Security: uutils/coreutils
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
id: groups= computed from real GID instead of effective GIDGHSA-47c7-qrm7-mqw7 published
May 30, 2026 by sylvestreModerate -
nohup: nohup.out created world-readable (0644) instead of owner-only (0600)GHSA-5gmx-24pj-xhwv published
Jul 29, 2026 by sylvestreModerate -
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)GHSA-p7h3-7q52-72w8 published
May 30, 2026 by sylvestreModerate -
uucore: safe_traversal TOCTOU protection only enabled on LinuxGHSA-w6xc-g9qj-vp32 published
May 30, 2026 by sylvestreLow -
touch: TOCTOU between existence check and create can truncate arbitrary filesGHSA-h73r-2j9w-ch42 published
Aug 7, 2026 by sylvestreModerate -
cp: -R reads device nodes as streams, destroying device semanticsGHSA-8vrf-r662-2w2v published
May 30, 2026 by sylvestreModerate -
mv: xattr-preservation TOCTOU on cross-device moves (inconsistent SELinux labels/caps)GHSA-p9fh-vm43-9xxc published
Jul 29, 2026 by sylvestreModerate -
mkdir: -m exposes directory with umask perms before chmod (race window)GHSA-mj6p-44ch-cq69 published
May 30, 2026 by sylvestreLow -
mv: file ownership lost on cross-device movesGHSA-p29p-xpv8-mh7g published
Jul 29, 2026 by sylvestreLow -
cp: -p retains setuid/setgid bits when chown failsGHSA-72j7-93r5-ffww published
Jul 29, 2026 by sylvestreLow