Количество 4
Количество 4
CVE-2026-35338
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown.
CVE-2026-35338
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown.
CVE-2026-35338
A vulnerability in the chmod utility of uutils coreutils allows users ...
GHSA-4c7q-4928-8445
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35338 A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35338 A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35338 A vulnerability in the chmod utility of uutils coreutils allows users ... | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
GHSA-4c7q-4928-8445 chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../) | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу