Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35348

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:*

EPSS

Процентиль: 3%
0.00134
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

CVSS3: 5.5
debian
4 месяца назад

The sort utility in uutils coreutils is vulnerable to a process panic ...

CVSS3: 5.5
github
4 месяца назад

uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths

EPSS

Процентиль: 3%
0.00134
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248