{"id":"GHSA-r9hw-mj3w-phcq","summary":"mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)","details":"uutils calls `mknod` *before* setting the SELinux context (GNU uses `setfscreatecon` first, labeling atomically). If `set_selinux_security_context` fails, cleanup uses `std::fs::remove_dir`, which cannot remove device nodes or FIFOs, leaving the mislabeled node behind.\n\n**Impact:** on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use `setfscreatecon` before `mknod`, abort on failure, and use `remove_file` for cleanup.\n\n**Remediation:** Acknowledged by Canonical.\n\n---\n_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.58. Credit: Zellic._","aliases":["CVE-2026-35361"],"modified":"2026-07-06T22:00:09.009832259Z","published":"2026-07-06T21:54:05Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-07-06T21:54:05Z","nvd_published_at":null,"cwe_ids":["CWE-281","CWE-459","CWE-732"]},"references":[{"type":"WEB","url":"https://github.com/uutils/coreutils/security/advisories/GHSA-r9hw-mj3w-phcq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35361"},{"type":"WEB","url":"https://github.com/uutils/coreutils/pull/10582"},{"type":"WEB","url":"https://github.com/uutils/coreutils/commit/42b2ad83cdcf6e959ecb378c5040c60d9c64becf"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"},{"type":"WEB","url":"https://github.com/uutils/coreutils/releases/tag/0.6.0"}],"affected":[{"package":{"name":"uu_mknod","ecosystem":"crates.io","purl":"pkg:cargo/uu_mknod"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r9hw-mj3w-phcq/GHSA-r9hw-mj3w-phcq.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"}]}