Количество 4
Количество 4
CVE-2026-35352
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.
CVE-2026-35352
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.
CVE-2026-35352
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ...
GHSA-9gh9-hwpr-rvqq
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35352 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-35352 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-35352 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
GHSA-9gh9-hwpr-rvqq uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | CVSS3: 7 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу