Количество 4
Количество 4
CVE-2026-35360
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.
CVE-2026-35360
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.
CVE-2026-35360
The touch utility in uutils coreutils is vulnerable to a Time-of-Check ...
GHSA-q6m9-xj2w-xmrc
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35360 The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss. | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35360 The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss. | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35360 The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
GHSA-q6m9-xj2w-xmrc uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | CVSS3: 6.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу