Vulnerability Description
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/uutils/coreutils
- https://github.com/uutils/coreutils/blob/0.9.0/src/uu/install/src/install.rs
- https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1
- https://github.com/uutils/coreutils/pull/13629
- https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
- https://www.vulncheck.com/advisories/uutils-coreutils-0.0.18-before-0.10.0-privi
- https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
FAQ
What is CVE-2026-93658?
CVE-2026-93658 is a vulnerability with a CVSS score of 7.0 (HIGH). uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the priv...
How severe is CVE-2026-93658?
CVE-2026-93658 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-93658?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.