CVE-2026-35358Disclosure(uutils / coreutils)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coreutils

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
coreutils

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-07-03: 1Technical Details · 2026-04-22: 1Technical Details · 2026-07-03: 104-2207-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Cybernews@__cybernews
    Disclosure

    @mikedoerfler @LundukeJournal Latest GNU Coreutils CVE: CVE-2017-18018, creating symlinks without permission(no cp involved) Latest rust coreutils CVE: CVE-2026-35358 which is actually 44 CVE's all across the board.

    Post summary

    The tweet alerts to two CVE identifiers for GNU and Rust Coreutils, highlighting a symlink creation flaw and a large cluster of related CVEs, but provides no exploit or patch information.

    100251502
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35358 The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preservin… https://www.cve.org/CVERecord?id=CVE-2026-35358

    Post summary

    The text announces a new vulnerability in the cp utility of uutils coreutils, detailing how recursive copies mishandle character and block device nodes.

    00000148
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuutilscoreutils-rust-

Explore more