PT-2026-95427 · Unknown · Uutils Coreutils
CVSS v4.0
7.3
High
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
uutils coreutils versions prior to 0.10.0
Description
The
install function applies setuid or setgid mode bits to installation destinations before finalizing ownership changes. On capability-restricted systems, if the ownership change operation fails, a setuid executable may remain owned by the privileged invoker. This allows an attacker to execute the leftover file to gain elevated privileges.Recommendations
Update uutils coreutils to version 0.10.0.
Exploit
Fix
LPE
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uutils Coreutils