| Name | CVE-2026-93658 |
| Description | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| rust-coreutils (PTS) | bookworm | 0.0.17-2 | vulnerable |
| trixie | 0.0.30-2 | vulnerable |
| forky | 0.10.0-1 | fixed |
| sid | 0.12.0-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| rust-coreutils | source | (unstable) | 0.10.0-1 | | | |
Notes
[trixie] - rust-coreutils <no-dsa> (Minor issue)
[bookworm] - rust-coreutils <postponed> (Limited support, minor issue)
https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
https://github.com/uutils/coreutils/pull/13629
Fixed by: https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55 (0.10.0)