Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh5c-xrmh-m794

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

uutils coreutils has an Untrusted Search Path

A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries (e.g., libnss_*.so.2) from the new root directory. If the NEWROOT is writable by an attacker, they can inject a malicious NSS module to execute arbitrary code as root, facilitating a full container escape or privilege escalation.

Пакеты

Наименование

coreutils

rust
Затронутые версииВерсия исправления

<= 0.8.0

Отсутствует

EPSS

Процентиль: 4%
0.00136
Низкий

7.8 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries (e.g., libnss_*.so.2) from the new root directory. If the NEWROOT is writable by an attacker, they can inject a malicious NSS module to execute arbitrary code as root, facilitating a full container escape or privilege escalation.

CVSS3: 7.8
nvd
4 месяца назад

A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries (e.g., libnss_*.so.2) from the new root directory. If the NEWROOT is writable by an attacker, they can inject a malicious NSS module to execute arbitrary code as root, facilitating a full container escape or privilege escalation.

CVSS3: 7.8
debian
4 месяца назад

A vulnerability exists in the chroot utility of uutils coreutils when ...

EPSS

Процентиль: 4%
0.00136
Низкий

7.8 High

CVSS3

Дефекты

CWE-426