


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the t…
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 18:02:07
Source:
nvd.nist.gov
Operating Systems
A vulnerability in the chmod utility of uutils coreutils allows bypassing the --preserve-root safety mechanism. The implementation only validates literal / paths without canonicalization. Attackers can use path variants like /../ or symbolic links to execute destructive recursive operations on the root filesystem. This can lead to system-wide permission loss through commands like chmod -R 000. The vulnerability enables complete system breakdown by circumventing critical safety protections.
Technical details
Mitigation steps:
Affected products:
uutils coreutils
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35338
https://github.com/uutils/coreutils/pull/10033
https://github.com/uutils/coreutils/releases/tag/0.6.0
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
