Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35348

Опубликовано: 22 апр. 2026
Источник: debian
EPSS Низкий

Описание

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-coreutilsfixed0.10.0-1package
rust-coreutilsno-dsatrixiepackage
rust-coreutilsno-dsabookwormpackage

Примечания

  • https://github.com/uutils/coreutils/issues/9696

  • https://github.com/uutils/coreutils/pull/11593

EPSS

Процентиль: 3%
0.00134
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

CVSS3: 5.5
nvd
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

CVSS3: 5.5
github
4 месяца назад

uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths

EPSS

Процентиль: 3%
0.00134
Низкий