


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the t…
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 22:11:22
Source:
nvd.nist.gov
Operating Systems
A vulnerability in the chmod utility of uutils coreutils allows bypassing the --preserve-root safety mechanism. The implementation fails to canonicalize paths, only checking for literal '/' matches. Attackers can use path variants like /../ or symbolic links to execute destructive recursive operations on the root filesystem. This can lead to system-wide permission loss through commands like chmod -R 000, potentially causing complete system breakdown. The vulnerability affects the core file permission management utility in Unix-like systems.
Technical details
Mitigation steps:
Affected products:
uutils coreutils
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35338
https://github.com/uutils/coreutils/pull/10033
https://github.com/uutils/coreutils/releases/tag/0.6.0
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
