{"id":"GHSA-fqf6-gxhh-2xhw","summary":"uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)","details":"`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `--backup`/`-b` and returns `BackupMode::None` when only `--suffix` is given. GNU enables backup mode when `--suffix` is used alone (defaulting to existing/numbered, or `$VERSION_CONTROL`). Affects `cp`, `install`, `mv`, `ln` which share this code.\n\n```\n# uutils: no backup created\n$ coreutils cp --suffix=.bak src dest      # dest.bak NOT created\n# GNU: dest.bak created\n$ cp --suffix=.bak src dest\n```\n\n**Impact:** users/scripts relying on `--suffix` to back up a file before overwrite get silent data loss; breaks GNU compatibility across four utilities. Recommendation: enable backup mode when `--suffix` is present.\n\n_Note: this is primarily a GNU-compatibility/data-safety divergence rather than a classic exploitable vulnerability — review whether it warrants a CVE._\n\n**Remediation:** Acknowledged by Canonical; fixed in PR #9741 (`uucore: use --suffix to enable backup mode`), commit `939ab037a`, merged 2025-12-21. `determine_backup_mode` now has a `--suffix`-alone branch that resolves the mode from `$VERSION_CONTROL` (defaulting to `existing`). Released in **uucore 0.6.0** and later (vulnerable: `\u003c 0.6.0`). Regression tests added in the same file: `test_backup_mode_suffix_without_backup_option` and `test_backup_mode_suffix_without_backup_option_with_env_var`.\n\n---\n_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.7. Credit: Zellic._","modified":"2026-07-07T19:45:19.172217860Z","published":"2026-07-07T19:36:17Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-07T19:36:17Z","nvd_published_at":null,"cwe_ids":["CWE-440","CWE-693"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/uutils/coreutils/security/advisories/GHSA-fqf6-gxhh-2xhw"},{"type":"WEB","url":"https://github.com/uutils/coreutils/pull/9741"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"}],"affected":[{"package":{"name":"uucore","ecosystem":"crates.io","purl":"pkg:cargo/uucore"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fqf6-gxhh-2xhw/GHSA-fqf6-gxhh-2xhw.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"}]}