CVE-2026-93658

NameCVE-2026-93658
Descriptionuutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-coreutils (PTS)bookworm0.0.17-2vulnerable
trixie0.0.30-2vulnerable
forky0.10.0-1fixed
sid0.12.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-coreutilssource(unstable)0.10.0-1

Notes

[trixie] - rust-coreutils <no-dsa> (Minor issue)
[bookworm] - rust-coreutils <postponed> (Limited support, minor issue)
https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
https://github.com/uutils/coreutils/pull/13629
Fixed by: https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55 (0.10.0)

Search for package or bug name: Reporting problems