CVE-2026-93658 PUBLISHED

uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

Assigner: VulnCheck
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.3

Product Status

Vendor uutils
Product coreutils
Versions Default: unaffected
  • affected from 0.0.18 to 0.10.0 (excl.)
  • Version 0.10.0 is unaffected

Credits

  • Ali Firas (thesmartshadow) finder

References

Problem Types

  • Improper Preservation of Permissions CWE