Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gh9-hwpr-rvqq

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.

Пакеты

Наименование

coreutils

rust
Затронутые версииВерсия исправления

<= 0.8.0

Отсутствует

EPSS

Процентиль: 4%
0.00147
Низкий

7 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7
ubuntu
4 месяца назад

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.

CVSS3: 7
nvd
4 месяца назад

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.

CVSS3: 7
debian
4 месяца назад

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ...

EPSS

Процентиль: 4%
0.00147
Низкий

7 High

CVSS3

Дефекты

CWE-367