Vulnerability Description
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device operations. The utility removes the destination path before recreating it through a copy operation. A local attacker with write access to the destination directory can exploit this window to replace the destination with a symbolic link. The subsequent privileged move operation will follow the symlink, allowing the attacker to redirect the write and overwrite an arbitrary target file with contents from the source.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uutils | Coreutils | - |
Related Weaknesses (CWE)
References
- https://github.com/uutils/coreutils/issues/10015ExploitIssue TrackingVendor Advisory
- https://github.com/uutils/coreutils/issues/10015ExploitIssue TrackingVendor Advisory
FAQ
What is CVE-2026-35364?
CVE-2026-35364 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device operations. The utility removes the destination path before recreating it throug...
How severe is CVE-2026-35364?
CVE-2026-35364 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35364?
Check the references section above for vendor advisories and patch information. Affected products include: Uutils Coreutils.