


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO becauseā¦
Published:
21 April 2026 at 22:00:00
Alert date:
22 April 2026 at 18:02:07
Source:
nvd.nist.gov
Operating Systems, Supply Chain & Dependencies
A vulnerability in uutils coreutils mkfifo allows unauthorized modification of file permissions when attempting to create a FIFO at a path where a file already exists. The mkfifo command fails to terminate properly and continues to execute a set_permissions call, changing existing file permissions to default mode (often 644). This can expose sensitive files like SSH private keys to other system users, creating a significant security risk for file access control.
Technical details
Mitigation steps:
Affected products:
uutils coreutils
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
