Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-35360

4 месяца назад

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-35360

4 месяца назад

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-35360

4 месяца назад

The touch utility in uutils coreutils is vulnerable to a Time-of-Check ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-q6m9-xj2w-xmrc

4 месяца назад

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-35360

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-35360

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creation using File::create(), which internally uses O_TRUNC. An attacker can exploit this window to create a file or swap a symlink at the target path, causing touch to truncate an existing file and leading to permanent data loss.

CVSS3: 6.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-35360

The touch utility in uutils coreutils is vulnerable to a Time-of-Check ...

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-q6m9-xj2w-xmrc

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу