Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47c7-qrm7-mqw7

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

id: groups= computed from real GID instead of effective GID

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.


Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.

Пакеты

Наименование

uu_id

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 1%
0.00108
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-273
CWE-863

Связанные уязвимости

CVSS3: 4.4
ubuntu
4 месяца назад

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.

CVSS3: 4.4
nvd
4 месяца назад

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.

CVSS3: 4.4
debian
4 месяца назад

The id utility in uutils coreutils miscalculates the groups= section o ...

EPSS

Процентиль: 1%
0.00108
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-273
CWE-863