PT-2026-95427 · Unknown · Uutils Coreutils

·

CVE-2026-93658

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions uutils coreutils versions prior to 0.10.0
Description The install function applies setuid or setgid mode bits to installation destinations before finalizing ownership changes. On capability-restricted systems, if the ownership change operation fails, a setuid executable may remain owned by the privileged invoker. This allows an attacker to execute the leftover file to gain elevated privileges.
Recommendations Update uutils coreutils to version 0.10.0.

Exploit

Fix

LPE

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93658
GHSA-CGG3-923W-V53M

Affected Products

Uutils Coreutils