PT-2026-34478 · Unknown · Uutils Coreutils

Zellic

·

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-35342

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description The mktemp utility fails to properly handle an empty TMPDIR environment variable. While other implementations fall back to /tmp when TMPDIR is an empty string, this implementation treats the empty string as a valid path, resulting in temporary files being created in the current working directory. This behavior can lead to unauthorized access to temporary data or information disclosure if the current working directory has more permissive access controls than the intended secure temporary directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-35342
GHSA-2CXP-XQ3C-MJXX

Affected Products

Uutils Coreutils