Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7h3-7q52-72w8

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.


Zellic finding 3.66. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.

Пакеты

Наименование

uu_printenv

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 7%
0.0017
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-116
CWE-754

Связанные уязвимости

CVSS3: 4.4
ubuntu
4 месяца назад

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
nvd
4 месяца назад

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
debian
4 месяца назад

The printenv utility in uutils coreutils fails to display environment ...

EPSS

Процентиль: 7%
0.0017
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-116
CWE-754