{"id":"GHSA-957r-r8gc-vv3h","summary":"uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries","details":"The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners.","aliases":["CVE-2026-35351"],"modified":"2026-09-10T03:51:01.367045573Z","published":"2026-04-22T18:31:45Z","database_specific":{"github_reviewed_at":"2026-04-29T23:18:01Z","nvd_published_at":"2026-04-22T17:16:37Z","cwe_ids":["CWE-281"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35351"},{"type":"WEB","url":"https://github.com/uutils/coreutils/issues/9714"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"}],"affected":[{"package":{"name":"coreutils","ecosystem":"crates.io","purl":"pkg:cargo/coreutils"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-957r-r8gc-vv3h/GHSA-957r-r8gc-vv3h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"}]}