[Git][security-tracker-team/security-tracker][master] Add more rust-coreutils issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Apr 22 23:02:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9708ec61 by Salvatore Bonaccorso at 2026-04-23T00:02:05+02:00
Add more rust-coreutils issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -194,41 +194,71 @@ CVE-2026-35368 (A vulnerability exists in the chroot utility of uutils coreutils
 	- rust-coreutils <unfixed>
 	NOTE: https://github.com/uutils/coreutils/issues/10327
 CVE-2026-35367 (The nohup utility in uutils coreutils creates its default output file, ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10021
 CVE-2026-35366 (The printenv utility in uutils coreutils fails to display environment  ...)
-	TODO: check
+	- rust-coreutils 0.6.0-1
+	NOTE: https://github.com/uutils/coreutils/issues/9701
+	NOTE: https://github.com/uutils/coreutils/pull/9728
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/0bfbbc00c7895c0fb6ea94987b4aab99e3d7ee52 (0.6.0)
 CVE-2026-35365 (The mv utility in uutils coreutils improperly handles directory trees  ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/pull/10546
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/9654e4abaf24449ef2279e9a16963edb5c8b8fef (0.7.0-1)
 CVE-2026-35364 (A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10015
 CVE-2026-35363 (A vulnerability in the rm utility of uutils coreutils allows the bypas ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/9749
 CVE-2026-35362 (The safe_traversal module in uutils coreutils, which provides protecti ...)
-	TODO: check
+	- rust-coreutils 0.6.0-1
+	NOTE: https://github.com/uutils/coreutils/pull/9792
+	NOTE: FIXED BY: https://github.com/uutils/coreutils/commit/30239e69a328e76d2377f2a0bc02fbde61c34280 (0.6.0)
 CVE-2026-35361 (The mknod utility in uutils coreutils fails to handle security labels  ...)
-	TODO: check
+	- rust-coreutils 0.6.0-1
+	NOTE: https://github.com/uutils/coreutils/pull/10582
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/42b2ad83cdcf6e959ecb378c5040c60d9c64becf (0.6.0)
 CVE-2026-35360 (The touch utility in uutils coreutils is vulnerable to a Time-of-Check ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10019
 CVE-2026-35359 (A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10017
 CVE-2026-35358 (The cp utility in uutils coreutils, when performing recursive copies ( ...)
-	TODO: check
+	- rust-coreutils 0.7.0-1
+	NOTE: https://github.com/uutils/coreutils/issues/9746
+	NOTE: https://github.com/uutils/coreutils/pull/11163
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/e6a3bb596f149628ba973eec3d099f3bb69f2464 (0.7.0)
 CVE-2026-35357 (The cp utility in uutils coreutils is vulnerable to an information dis ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10011
 CVE-2026-35356 (A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the in ...)
-	TODO: check
+	- rust-coreutils 0.7.0-1
+	NOTE: https://github.com/uutils/coreutils/pull/10140
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/0c41299975f3c1e21cf5ca968d42cad55ceb42a1 (0.7.0)
 CVE-2026-35355 (The install utility in uutils coreutils is vulnerable to a Time-of-Che ...)
-	TODO: check
+	- rust-coreutils 0.6.0-1
+	NOTE: https://github.com/uutils/coreutils/pull/10067
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/b5bbabc18a1121908848d836f869a4e98eb63886 (0.6.0)
 CVE-2026-35354 (A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10014
 CVE-2026-35353 (The mkdir utility in uutils coreutils incorrectly applies permissions  ...)
-	TODO: check
+	- rust-coreutils 0.6.0-1
+	NOTE: https://github.com/uutils/coreutils/pull/10036
+	NOTE: Fixed by; https://github.com/uutils/coreutils/commit/037b9583bc03d814e8516df54ebcda6f681fe1f8 (0.6.0)
 CVE-2026-35352 (A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/10020
 CVE-2026-35351 (The mv utility in uutils coreutils fails to preserve file ownership du ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/9714
+	NOTE: https://github.com/uutils/coreutils/pull/11706
+	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/874efa7cc3361cb5af2a97db869147f910bcab44
 CVE-2026-35350 (The cp utility in uutils coreutils fails to properly handle setuid and ...)
-	TODO: check
+	- rust-coreutils <unfixed>
+	NOTE: https://github.com/uutils/coreutils/issues/9750
 CVE-2026-35349 (A vulnerability in the rm utility of uutils coreutils allows a bypass  ...)
 	TODO: check
 CVE-2026-35348 (The sort utility in uutils coreutils is vulnerable to a process panic  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9708ec6123dc1747285c4e0c953b45ee502e67ef

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9708ec6123dc1747285c4e0c953b45ee502e67ef
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260422/7c83f400/attachment.htm>


More information about the debian-security-tracker-commits mailing list