GHSA-pmf6-rcx4-v53v

Suggest an improvement
Source
https://github.com/advisories/GHSA-pmf6-rcx4-v53v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pmf6-rcx4-v53v/GHSA-pmf6-rcx4-v53v.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-pmf6-rcx4-v53v
Aliases
  • CVE-2026-35341
Published
2026-07-06T21:53:34Z
Modified
2026-07-06T22:00:08.774187872Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
mkfifo: permissions of an existing file are changed after FIFO creation fails
Details

When mkfifo() fails (e.g. target already exists), the code shows an error but is missing a continue;, so it falls through to fs::set_permissions and changes the permissions of the pre-existing file to the default FIFO mode (0o666 & umask -> 0644).

$ touch secret; chmod 000 secret
$ coreutils mkfifo secret fifo3 fifo4
mkfifo: cannot create fifo 'secret': File exists
$ ll secret      # uutils:
prw-r--r-- secret   # changed to 644 (GNU leaves it 000)

Impact: an attacker (or user error) can relax permissions on sensitive owner-only files such as SSH private keys, exposing them to other users. Recommendation: add continue; after the error.

Remediation: Acknowledged by Canonical; fixed in PR #10376.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.8. Credit: Zellic.

Upstream tracking issue: https://github.com/uutils/coreutils/issues/10020 ยท CVE-2026-35341

Database specific
{
    "cwe_ids": [
        "CWE-281",
        "CWE-732"
    ],
    "github_reviewed": true,
    "severity": "HIGH",
    "github_reviewed_at": "2026-07-06T21:53:34Z",
    "nvd_published_at": null
}
References

Affected packages

crates.io / uu_mkfifo

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pmf6-rcx4-v53v/GHSA-pmf6-rcx4-v53v.json"