Количество 4
Количество 4
CVE-2026-35350
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.
CVE-2026-35350
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.
CVE-2026-35350
The cp utility in uutils coreutils fails to properly handle setuid and ...
GHSA-x2wv-9p67-mh9w
uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35350 The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved. | CVSS3: 6.6 | 0% Низкий | 4 месяца назад | |
CVE-2026-35350 The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved. | CVSS3: 6.6 | 0% Низкий | 4 месяца назад | |
CVE-2026-35350 The cp utility in uutils coreutils fails to properly handle setuid and ... | CVSS3: 6.6 | 0% Низкий | 4 месяца назад | |
GHSA-x2wv-9p67-mh9w uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails | CVSS3: 6.6 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу