Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35358

Опубликовано: 22 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.4

Описание

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.

РелизСтатусПримечание
devel

not-affected

0.8.0-0ubuntu3
esm-apps/noble

needed

jammy

DNE

noble

needed

questing

ignored

end of life, was needed
resolute

not-affected

0.8.0-0ubuntu3
upstream

released

0.7.0-1

Показывать по

EPSS

Процентиль: 8%
0.00178
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
4 месяца назад

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.

CVSS3: 4.4
debian
4 месяца назад

The cp utility in uutils coreutils, when performing recursive copies ( ...

CVSS3: 4.4
github
около 1 месяца назад

cp: -R reads device nodes as streams, destroying device semantics

EPSS

Процентиль: 8%
0.00178
Низкий

4.4 Medium

CVSS3