Ubuntu reportedly postponed its planned adoption of the Rust-based uutils coreutils implementation for core commands including cp, mv, and rm, retaining GNU Coreutils for Ubuntu 26.04 LTS amid security and reliability concerns. The cross-platform Rust project had been slated to become the default implementation, but filesystem-path handling flaws raised concerns about its use in privileged system operations.
The affected utilities reportedly contain symlink time-of-check-to-time-of-use (TOCTOU) race conditions: a local unprivileged user could replace an object after validation but before the command operates on it, redirecting a root-run operation to unintended files or directories. A cited attack path involves the root-executed /etc/cron.daily/apport cleanup job processing the user-writable /var/crash directory, potentially enabling unintended file operations or local privilege escalation.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Ubuntu delayed its planned replacement of GNU Coreutils with Rust-based uutils coreutils for cp, mv, and rm after security and reliability concerns were identified. The reported symlink-handling TOCTOU races could allow a local unprivileged user to influence root-run file operations; a proof of concept targeted Apport's root-run cleanup of the user-writable /var/crash directory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
opennet.ru
Open sourceopennet.me
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.