PT-2026-34486 · Unknown · Uutils Coreutils

Zellic

·

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-35350

CVSS v3.1

6.6

Medium

AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description The cp utility fails to properly handle setuid and setgid bits when ownership preservation fails. When using the '-p' (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2026-35350

Affected Products

Uutils Coreutils