Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35353

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user environments, this introduces a brief window where a directory intended to be private is accessible to other users, potentially leading to unauthorized data access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*
Версия до 0.6.0 (исключая)

EPSS

Процентиль: 1%
0.00102
Низкий

3.3 Low

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user environments, this introduces a brief window where a directory intended to be private is accessible to other users, potentially leading to unauthorized data access.

CVSS3: 3.3
debian
4 месяца назад

The mkdir utility in uutils coreutils incorrectly applies permissions ...

CVSS3: 3.3
github
около 1 месяца назад

mkdir: -m exposes directory with umask perms before chmod (race window)

EPSS

Процентиль: 1%
0.00102
Низкий

3.3 Low

CVSS3

Дефекты

CWE-367