CVE-2026-35352

HIGH7.0EPSS 0.01%

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

發布日:2026/4/22修改日:2026/6/2
也稱為:GHSA-9gh9-hwpr-rvqqCGA-6w2h-m6j7-j2gq

描述

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.0CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(7)