Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-957r-r8gc-vv3h

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries

The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners.

Пакеты

Наименование

coreutils

rust
Затронутые версииВерсия исправления

<= 0.8.0

Отсутствует

EPSS

Процентиль: 3%
0.00132
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 4.2
ubuntu
4 месяца назад

The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners.

CVSS3: 4.2
nvd
4 месяца назад

The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners.

CVSS3: 4.2
debian
4 месяца назад

The mv utility in uutils coreutils fails to preserve file ownership du ...

EPSS

Процентиль: 3%
0.00132
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-281