Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-239g-2685-54x3

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

copy_file in install/src/install.rs removes the destination then recreates it by pathname via File::create / fs::copy without O_EXCL/create_new. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the write.

Impact: when install runs privileged into an attacker-writable directory (staging/build paths), the race allows redirecting writes to arbitrary files and overwriting sensitive system files (/etc/passwd, /etc/shadow). Recommendation: create atomically with create_new/O_EXCL and copy via the opened fd rather than reopening by path.

Remediation: Acknowledged by Canonical; fixed in commit b5bbabc1.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.50. Credit: Zellic.

Пакеты

Наименование

uu_install

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 2%
0.00118
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-367
CWE-59

Связанные уязвимости

CVSS3: 6.3
ubuntu
3 месяца назад

The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local attacker can exploit the window between the unlink and the subsequent creation to swap the path with a symbolic link, allowing them to redirect privileged writes to overwrite arbitrary system files.

CVSS3: 6.3
nvd
3 месяца назад

The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local attacker can exploit the window between the unlink and the subsequent creation to swap the path with a symbolic link, allowing them to redirect privileged writes to overwrite arbitrary system files.

CVSS3: 6.3
debian
3 месяца назад

The install utility in uutils coreutils is vulnerable to a Time-of-Che ...

EPSS

Процентиль: 2%
0.00118
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-367
CWE-59