Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-35350

4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2026-35350

4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2026-35350

4 месяца назад

The cp utility in uutils coreutils fails to properly handle setuid and ...

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-x2wv-9p67-mh9w

4 месяца назад

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-35350

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-35350

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.

CVSS3: 6.6
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-35350

The cp utility in uutils coreutils fails to properly handle setuid and ...

CVSS3: 6.6
0%
Низкий
4 месяца назад
github логотип
GHSA-x2wv-9p67-mh9w

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

CVSS3: 6.6
0%
Низкий
4 месяца назад

Уязвимостей на страницу