PT-2026-34507 · Unknown · Uutils Coreutils

Zellic

·

Published

2026-04-22

·

Updated

2026-05-04

·

CVE-2026-35371

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions uutils coreutils (affected versions not specified)
Description The id utility exhibits incorrect behavior in its pretty print output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID during the name lookup for the effective user, leading to misleading diagnostic output. This may cause automated scripts or system administrators to make incorrect decisions regarding access control or file permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2026-35371
GHSA-53GR-WMF4-8HH3

Affected Products

Uutils Coreutils