{"id":"GHSA-x2wv-9p67-mh9w","summary":"uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails","details":"The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.","aliases":["CVE-2026-35350"],"modified":"2026-09-10T03:51:03.765658653Z","published":"2026-04-22T18:31:45Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-29T23:18:25Z","nvd_published_at":"2026-04-22T17:16:37Z","cwe_ids":["CWE-281"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35350"},{"type":"WEB","url":"https://github.com/uutils/coreutils/issues/9750"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"}],"affected":[{"package":{"name":"coreutils","ecosystem":"crates.io","purl":"pkg:cargo/coreutils"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-x2wv-9p67-mh9w/GHSA-x2wv-9p67-mh9w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"}]}