


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO becauseā¦
Published:
21 April 2026 at 22:00:00
Alert date:
22 April 2026 at 22:11:22
Source:
nvd.nist.gov
Operating Systems, Supply Chain & Dependencies
A vulnerability in uutils coreutils mkfifo command allows unauthorized modification of file permissions on existing files. When mkfifo fails to create a FIFO due to an existing file at the target path, it incorrectly continues execution and calls set_permissions, changing the existing file's permissions to default mode (typically 644). This can expose sensitive files like SSH private keys to unauthorized users on the system by making them readable by others when they should have restricted permissions.
Technical details
Mitigation steps:
Affected products:
uutils coreutils
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
