PT-2026-34504 · Unknown · Uutils Coreutils

Zellic

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-35368

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description A flaw in the chroot utility occurs when the --userspec option is used. The utility calls the getPwnam() function to resolve user specifications after entering the chroot environment but before relinquishing root privileges. On glibc-based systems, this process triggers the Name Service Switch (NSS), which may load shared libraries such as 'libnss *.so.2' from the new root directory. If an attacker has write access to the new root directory, they can inject a malicious NSS module to execute arbitrary code with root privileges, potentially leading to privilege escalation or a full container escape.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-35368
GHSA-MH5C-XRMH-M794

Affected Products

Uutils Coreutils