Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35350

Опубликовано: 22 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.6

Описание

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

РелизСтатусПримечание
devel

needed

esm-apps/noble

needed

jammy

DNE

noble

needed

questing

ignored

end of life, was needed
resolute

needed

upstream

needed

Показывать по

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
nvd
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
debian
4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and ...

CVSS3: 6.6
github
4 месяца назад

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3