Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35362

Опубликовано: 22 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 3.6

Описание

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.

РелизСтатусПримечание
devel

not-affected

0.8.0-0ubuntu3
esm-apps/noble

needed

jammy

DNE

noble

needed

questing

ignored

end of life, was needed
resolute

not-affected

0.8.0-0ubuntu3
upstream

released

0.6.0-1

Показывать по

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
nvd
4 месяца назад

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.

CVSS3: 3.6
debian
4 месяца назад

The safe_traversal module in uutils coreutils, which provides protecti ...

CVSS3: 3.6
github
около 1 месяца назад

uucore: safe_traversal TOCTOU protection only enabled on Linux

3.6 Low

CVSS3