Количество 4
Количество 4
CVE-2026-35348
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.
CVE-2026-35348
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.
CVE-2026-35348
The sort utility in uutils coreutils is vulnerable to a process panic ...
GHSA-f2jv-wjjc-2c94
uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35348 The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-35348 The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-35348 The sort utility in uutils coreutils is vulnerable to a process panic ... | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-f2jv-wjjc-2c94 uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths | CVSS3: 5.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу