GHSA-w6xc-g9qj-vp32

Suggest an improvement
Source
https://github.com/advisories/GHSA-w6xc-g9qj-vp32
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-w6xc-g9qj-vp32/GHSA-w6xc-g9qj-vp32.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-w6xc-g9qj-vp32
Aliases
Published
2026-07-06T20:25:15Z
Modified
2026-07-06T20:31:02.772187074Z
Severity
  • 3.6 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
uucore: safe_traversal TOCTOU protection only enabled on Linux
Details

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.


Zellic finding 3.59. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-367"
    ],
    "severity": "LOW",
    "github_reviewed_at": "2026-07-06T20:25:15Z",
    "nvd_published_at": null
}
References

Affected packages

crates.io / uucore

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-w6xc-g9qj-vp32/GHSA-w6xc-g9qj-vp32.json"