CVE-2026-35352 affects the mkfifo utility in uutils coreutils. According to the provided content, mkfifo creates a FIFO first and then performs a path-based chmod() on that pathname to apply the requested permissions. This introduces a time-of-check to time-of-use race window between FIFO creation and permission adjustment. The CVE description states that a local attacker with write access to the parent directory can replace the newly created FIFO with a symbolic link before chmod() executes, causing the chmod operation to be redirected to an arbitrary file. The supporting discussion also notes a related, directly observed issue in uutils coreutils 0.8.0: mkfifo temporarily sets umask to 000 and creates the FIFO with mode 0666 before later restricting permissions, which can expose the FIFO to other local users during that window. The oss-sec discussion disputes whether the symlink-swap scenario is broadly exploitable in sticky directories such as /tmp, but confirms that exploitation would be more plausible when the victim creates the FIFO inside an attacker-controlled writable directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.