GHSA-r9hw-mj3w-phcq

Suggest an improvement
Source
https://github.com/advisories/GHSA-r9hw-mj3w-phcq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r9hw-mj3w-phcq/GHSA-r9hw-mj3w-phcq.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-r9hw-mj3w-phcq
Aliases
Published
2026-07-06T21:54:05Z
Modified
2026-07-06T22:00:08.751384292Z
Severity
  • 3.4 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Details

uutils calls mknod before setting the SELinux context (GNU uses setfscreatecon first, labeling atomically). If set_selinux_security_context fails, cleanup uses std::fs::remove_dir, which cannot remove device nodes or FIFOs, leaving the mislabeled node behind.

Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use setfscreatecon before mknod, abort on failure, and use remove_file for cleanup.

Remediation: Acknowledged by Canonical.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.58. Credit: Zellic.

Database specific
{
    "severity": "LOW",
    "github_reviewed_at": "2026-07-06T21:54:05Z",
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-281",
        "CWE-459",
        "CWE-732"
    ],
    "github_reviewed": true
}
References

Affected packages

crates.io / uu_mknod

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r9hw-mj3w-phcq/GHSA-r9hw-mj3w-phcq.json"