Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c7q-4928-8445

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

Chmoder::chmod() only compares the literal argument against Path::new("/"), so the --preserve-root guard is bypassed by any path that resolves to root — a symlink to / or simply /../.

if self.recursive && self.preserve_root && file == Path::new("/") { return Err(ChmodError::PreserveRoot("/".to_string()).into()); }

PoC — recursively chmods the entire filesystem to 000 despite --preserve-root:

chmod -R --preserve-root 000 /../ -v

Impact: --preserve-root is the documented safeguard against destructive recursive operations on /. Bypassing it allows chmod -R to alter permissions across the whole filesystem, causing a complete system breakdown. Recommendation: canonicalize the target path before comparing against root.

Remediation: Acknowledged by Canonical; fixed in commit 413055b3.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.1. Credit: Zellic.

Пакеты

Наименование

uu_chmod

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 7%
0.00175
Низкий

7.3 High

CVSS3

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown.

CVSS3: 7.3
nvd
4 месяца назад

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown.

CVSS3: 7.3
debian
4 месяца назад

A vulnerability in the chmod utility of uutils coreutils allows users ...

EPSS

Процентиль: 7%
0.00175
Низкий

7.3 High

CVSS3

Дефекты

CWE-22
CWE-59