Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj6p-44ch-cq69

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

mkdir: -m exposes directory with umask perms before chmod (race window)

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user environments, this introduces a brief window where a directory intended to be private is accessible to other users, potentially leading to unauthorized data access.


Zellic finding 3.48. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.

Пакеты

Наименование

uu_mkdir

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 1%
0.00102
Низкий

3.3 Low

CVSS3

Дефекты

CWE-362
CWE-367
CWE-732

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user environments, this introduces a brief window where a directory intended to be private is accessible to other users, potentially leading to unauthorized data access.

CVSS3: 3.3
nvd
4 месяца назад

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user environments, this introduces a brief window where a directory intended to be private is accessible to other users, potentially leading to unauthorized data access.

CVSS3: 3.3
debian
4 месяца назад

The mkdir utility in uutils coreutils incorrectly applies permissions ...

EPSS

Процентиль: 1%
0.00102
Низкий

3.3 Low

CVSS3

Дефекты

CWE-362
CWE-367
CWE-732