


Perceptive Security
SOC/SIEM Consultancy

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-bas…
Published:
21 April 2026 at 22:00:00
Alert date:
22 April 2026 at 22:11:22
Source:
nvd.nist.gov
Operating Systems, Supply Chain & Dependencies
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability exists in the mkfifo utility of uutils coreutils. The flaw occurs when the utility creates a FIFO and then performs a path-based chmod operation to set permissions. A local attacker with write access to the parent directory can exploit this timing window by swapping the newly created FIFO for a symbolic link between these two operations. This causes the chmod call to be redirected to an arbitrary file, potentially enabling privilege escalation if the mkfifo utility is executed with elevated privileges.
Technical details
Mitigation steps:
Affected products:
uutils coreutils
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
