CVE Explorer
CVE-2026-35339
The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if errors were encountered on previous files, such as 'Operation not permitted'. Scripts relying on these exit codes may proceed under a false sense of success while sensitive files remain with restrictive o
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/uutils","defaultStatus":"unaffected","packageName":"coreutils","platforms":["Linux","Unix","macOS"],"product":"coreutils","repo":"https://github.com/uutils/coreutils","vendor":"Uutils","versions":[{"lessThan":"0.6.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8dcab114843c09b5df1136aef57cd952468fc1e1e32c3324ed22b0deed5c0ea7 · sha256:b570aef0157a3613… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8dcab114843c09b5df1136aef57cd952468fc1e1e32c3324ed22b0deed5c0ea7 · sha256:b570aef0157a3613… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-253","description":"CWE-253: Incorrect Check of Function Return Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dcab114843c09b5df1136aef57cd952468fc1e1e32c3324ed22b0deed5c0ea7 · sha256:b570aef0157a3613… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["patch","issue-tracking"],"url":"https://github.com/uutils/coreutils/pull/9793"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dcab114843c09b5df1136aef57cd952468fc1e1e32c3324ed22b0deed5c0ea7 · sha256:b570aef0157a3613… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://github.com/uutils/coreutils/releases/tag/0.6.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dcab114843c09b5df1136aef57cd952468fc1e1e32c3324ed22b0deed5c0ea7 · sha256:b570aef0157a3613… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.