Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35360

Опубликовано: 22 апр. 2026
Источник: debian
EPSS Низкий

Описание

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-coreutilsfixed0.10.0-1package
rust-coreutilsno-dsatrixiepackage
rust-coreutilsno-dsabookwormpackage

Примечания

  • https://github.com/uutils/coreutils/issues/10019

  • Fixed by: https://github.com/uutils/coreutils/commit/ca0c842e71a9f75b31c87f701952f9e174a320ce (0.10.0)

EPSS

Процентиль: 1%
0.00104
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
4 месяца назад

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
nvd
4 месяца назад

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
github
4 месяца назад

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

EPSS

Процентиль: 1%
0.00104
Низкий