CVE-2026-35352Disclosure(uutils / coreutils)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch uutils coreutils systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation if the utility is run with elevated privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coreutils

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
coreutils

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 104-2204-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    ```json { "x": "🚨 HIGH: CVE-2026-35352 (CVSS 7.0)\n\nTOCTOU race condition in uutils coreutils mkfifo allows local attackers to redirect chmod operations via symlink swap, enabling privilege escalation.\n\nAffected: uutils coreutils mkfifo\n\n#CVE #Vulnerability #PatchNow #ThreatIntel", "linkedin": "🚨 HIGH SEVERITY ALERT\n\nCVE-2026-35352: TOCTOU Race Condition in uutils coreutils mkfifo\nCVSS Score: 7.0 (High)\nVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\n\nTHREAT SUMMARY:\nA Time-of-Check to Time-of-Use (TOCTOU) race condition has been identified in the mkfifo utility of uutils coreutils. This vulnerability allows local attackers with write access to the parent directory to achieve privilege escalation.\n\nKEY DETAILS:\n• Affected Product: uutils coreutils mkfifo utility\n• Vulnerability Type: TOCTOU race condition (CWE-367)\n• Attack Vector: Local\n• Attack Complexity: High\n• Privileges Required: Low\n• Impact: High confidentiality, integrity, and availability impact\n\nATTACK MECHANISM:\nThe mkfifo utility creates a FIFO and then performs a path-based chmod operation to set permissions. An attacker can exploit the time gap between FIFO creation and permission setting by swapping the newly created FIFO with a symbolic link. This redirects the chmod call to an arbitrary file, potentially enabling privilege escalation when the utility runs with elevated privileges.\n\nRECOMMENDED ACTIONS:\n• Identify systems running uutils coreutils mkfifo\n• Monitor for available patches from the uutils project\n• Restrict write access to directories where mkfifo operations occur\n• Review processes running mkfifo with elevated privileges\n• Implement file integrity monitoring on critical system files\n\nSOC teams should prioritize detection of suspicious symlink creation patterns in directories where FIFO operations are common.\n\n#CVE #Vulnerability #PatchNow #ThreatIntel #DFIR #CyberSecurity", "reddit": "**HIGH SEVERITY: CVE-2026-35352 - TOCTOU Race Condition in uutils coreutils mkfifo**\n\n**CVSS Score:** 7.0 (High)\n**CVSS Vector:** CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\n**CWE:** CWE-367 (Time-of-Check Time-of-Use Race Condition)\n\n---\n\n## Vulnerability Overview\n\nA Time-of-Check to Time-of-Use (TOCTOU) race condition has been discovered in the mkfifo utility of uutils coreutils. This vulnerability allows a local attacker with write access to the parent directory to redirect chmod operations to arbitrary files, potentially leading to privilege escalation.\n\n## Affected Products\n\n- **uutils coreutils** - mkfifo utility\n- Specific affected versions: TBD (monitor vendor advisories)\n\n## Technical Details\n\nThe vulnerability exists in the mkfifo utility's file creation and permission-setting workflow:\n\n1. The utility creates a FIFO (named pipe) at a specified path\n2. A path-based chmod operation is then performed to set appropriate permissions\n3. A race window exists between these two operations\n\nAn attacker with write access to the parent directory can exploit this race condition by:\n\n1. Monitoring for mkfifo operations\n2. Immediately replacing the newly created FIFO with a symbolic link pointing to a target file\n3.

    Post summary

    The post announces CVE‑2026‑35352, a TIME‑OF‑CHECK/TO‑USE race condition in the uutils coreutils mkfifo that permits local privilege escalation, and provides detailed technical information and patch/mitigation recommendations.

    0000081
    25 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35352 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chm… https://www.cve.org/CVERecord?id=CVE-2026-35352

    Post summary

    The post announces a TOCTOU race condition in the mkfifo utility of uutils coreutils, providing basic technical details but no evidence of exploitation or mitigation.

    00000139
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuutilscoreutils-rust-

Explore more