Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35350

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uutils:coreutils:-:*:*:*:*:rust:*:*

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 6.6
ubuntu
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
debian
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and ...

CVSS3: 6.6
github
4 месяца назад

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-281