Описание
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
copy_file in install/src/install.rs removes the destination then recreates it by pathname via File::create / fs::copy without O_EXCL/create_new. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the write.
Impact: when install runs privileged into an attacker-writable directory (staging/build paths), the race allows redirecting writes to arbitrary files and overwriting sensitive system files (/etc/passwd, /etc/shadow). Recommendation: create atomically with create_new/O_EXCL and copy via the opened fd rather than reopening by path.
Remediation: Acknowledged by Canonical; fixed in commit b5bbabc1.
Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.50. Credit: Zellic.
Ссылки
- https://github.com/uutils/coreutils/security/advisories/GHSA-239g-2685-54x3
- https://nvd.nist.gov/vuln/detail/CVE-2026-35355
- https://github.com/uutils/coreutils/pull/10067
- https://github.com/uutils/coreutils/commit/b5bbabc18a1121908848d836f869a4e98eb63886
- https://github.com/uutils/coreutils/releases/tag/0.6.0
Пакеты
uu_install
< 0.6.0
0.6.0
Связанные уязвимости
The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local attacker can exploit the window between the unlink and the subsequent creation to swap the path with a symbolic link, allowing them to redirect privileged writes to overwrite arbitrary system files.
The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local attacker can exploit the window between the unlink and the subsequent creation to swap the path with a symbolic link, allowing them to redirect privileged writes to overwrite arbitrary system files.
The install utility in uutils coreutils is vulnerable to a Time-of-Che ...