Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35362

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 3.6
EPSS Низкий

Описание

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*
Версия до 0.6.0 (исключая)

EPSS

Процентиль: 8%
0.0018
Низкий

3.6 Low

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 3.6
ubuntu
4 месяца назад

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.

CVSS3: 3.6
debian
4 месяца назад

The safe_traversal module in uutils coreutils, which provides protecti ...

CVSS3: 3.6
github
около 1 месяца назад

uucore: safe_traversal TOCTOU protection only enabled on Linux

EPSS

Процентиль: 8%
0.0018
Низкий

3.6 Low

CVSS3

Дефекты

CWE-367