An oss-sec disclosure reported that the Rust-based uutils coreutils project contains 113 audit findings, including 44 assigned CVEs (CVE-2026-35338 through CVE-2026-35381), after a Zellic review tied to Canonical's evaluation of the package for Ubuntu 26.04. Canonical said most issues had been resolved, but the report said multiple vulnerabilities were still reproducible on a fully updated Ubuntu 26.04 system running uutils coreutils 0.8.0. Because of TOCTOU race conditions, Canonical kept the GNU implementations of cp, mv, and rm rather than replacing them with uutils versions.
The published issues span mkfifo, nohup, tail, and other utilities, and include symlink attacks, unsafe file creation, permission and ownership handling flaws, incorrect exit codes, UTF-8 parsing bugs, and logic errors that could enable privilege escalation, information disclosure, denial of service, data corruption, or destructive filesystem operations. A follow-up oss-sec reply focused on the mkfifo case, agreeing that the race condition remained valid while clarifying that the example's initial FIFO permissions would be shaped by umask(002), producing mode 664 rather than 666 before a later chmod(2) call.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Ubuntu switched the cp command back to GNU coreutils after a compatibility bug in Rust coreutils cp broke Ubuntu image builds and live media ISO construction. The failure was tied to different handling of the "-L" argument, and an upstream fix had been proposed but not yet merged.
In a follow-up oss-sec discussion, Jan Schaumann said the reported mkfifo race condition was not in dispute but clarified that the initial FIFO permissions in the example would be affected by umask(002). He noted the FIFO would initially be mode 664 rather than 666, making it group-writable rather than world-writable before a later chmod(2) call.
Collin Funk reported that multiple vulnerabilities remained reproducible on a fully updated Ubuntu 26.04 system running uutils coreutils 0.8.0, including examples involving mkfifo, nohup, and a symlink-following issue in tail. The same disclosure enumerated CVE-2026-35338 through CVE-2026-35381 across affected uutils utilities.
Canonical said it would retain the GNU implementations of cp, mv, and rm in Ubuntu 26.04 rather than replace them with uutils versions because of TOCTOU race-condition concerns. Canonical also stated that most audit issues had been resolved, though it did not clearly specify which remained open.
A Zellic security audit of the Rust-based uutils coreutils project identified 113 issues, 44 of which were assigned CVEs. The findings covered race conditions, symlink attacks, permission and ownership flaws, unsafe file creation, logic errors, and other bugs affecting multiple utilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
phoronix.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.