Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35350

Опубликовано: 22 апр. 2026
Источник: debian
EPSS Низкий

Описание

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-coreutilsfixed0.8.0-1package
rust-coreutilsno-dsatrixiepackage
rust-coreutilsno-dsabookwormpackage

Примечания

  • https://github.com/uutils/coreutils/issues/9750

EPSS

Процентиль: 3%
0.00125
Низкий

Связанные уязвимости

CVSS3: 6.6
ubuntu
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
nvd
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
github
4 месяца назад

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

EPSS

Процентиль: 3%
0.00125
Низкий
Уязвимость CVE-2026-35350