PT-2026-34494 · Unknown · Uutils Coreutils

Zellic

·

Published

2026-04-22

·

Updated

2026-05-04

·

CVE-2026-35358

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description The cp utility incorrectly handles character and block device nodes during recursive copies using the -R flag. Instead of preserving the device nodes via mknod, the utility treats them as stream sources and reads their bytes into regular files at the destination. This destruction of device semantics can result in runtime denial of service, potentially causing process hangs or disk exhaustion when reading from unbounded device nodes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35358
GHSA-67HP-F6HQ-2H6G

Affected Products

Uutils Coreutils