Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2jv-wjjc-2c94

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

Пакеты

Наименование

coreutils

rust
Затронутые версииВерсия исправления

<= 0.8.0

Отсутствует

EPSS

Процентиль: 3%
0.00134
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

CVSS3: 5.5
nvd
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

CVSS3: 5.5
debian
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic ...

EPSS

Процентиль: 3%
0.00134
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248