GHSA-fqf6-gxhh-2xhw

Suggest an improvement
Source
https://github.com/advisories/GHSA-fqf6-gxhh-2xhw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fqf6-gxhh-2xhw/GHSA-fqf6-gxhh-2xhw.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-fqf6-gxhh-2xhw
Published
2026-07-07T19:36:17Z
Modified
2026-07-07T19:45:16.784949314Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
Details

determine_backup_mode in src/uucore/src/lib/features/backup_control.rs only checks --backup/-b and returns BackupMode::None when only --suffix is given. GNU enables backup mode when --suffix is used alone (defaulting to existing/numbered, or $VERSION_CONTROL). Affects cp, install, mv, ln which share this code.

# uutils: no backup created
$ coreutils cp --suffix=.bak src dest      # dest.bak NOT created
# GNU: dest.bak created
$ cp --suffix=.bak src dest

Impact: users/scripts relying on --suffix to back up a file before overwrite get silent data loss; breaks GNU compatibility across four utilities. Recommendation: enable backup mode when --suffix is present.

Note: this is primarily a GNU-compatibility/data-safety divergence rather than a classic exploitable vulnerability — review whether it warrants a CVE.

Remediation: Acknowledged by Canonical; fixed in PR #9741 (uucore: use --suffix to enable backup mode), commit 939ab037a, merged 2025-12-21. determine_backup_mode now has a --suffix-alone branch that resolves the mode from $VERSION_CONTROL (defaulting to existing). Released in uucore 0.6.0 and later (vulnerable: < 0.6.0). Regression tests added in the same file: test_backup_mode_suffix_without_backup_option and test_backup_mode_suffix_without_backup_option_with_env_var.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.7. Credit: Zellic.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-440",
        "CWE-693"
    ],
    "severity": "HIGH",
    "github_reviewed_at": "2026-07-07T19:36:17Z",
    "nvd_published_at": null
}
References

Affected packages

crates.io / uucore

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fqf6-gxhh-2xhw/GHSA-fqf6-gxhh-2xhw.json"