CVE Explorer
CVE-2026-35341
A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permissions call. This results in the existing file's permissions being changed to the default mode (often 644 after umask), potentially exposing sensitive files such as SSH private keys to other users on t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/uutils","defaultStatus":"affected","packageName":"coreutils","platforms":["Linux","Unix","macOS"],"product":"coreutils","repo":"https://github.com/uutils/coreutils","vendor":"Uutils"}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e148745af3dee6bc358118eb812e7e90213f4a52c2442ff3edd5e64d47480735 · sha256:b98cd41a522447fd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e148745af3dee6bc358118eb812e7e90213f4a52c2442ff3edd5e64d47480735 · sha256:b98cd41a522447fd… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-732","description":"CWE-732: Incorrect Permission Assignment for Critical Resource","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e148745af3dee6bc358118eb812e7e90213f4a52c2442ff3edd5e64d47480735 · sha256:b98cd41a522447fd… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["issue-tracking"],"url":"https://github.com/uutils/coreutils/issues/10020"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e148745af3dee6bc358118eb812e7e90213f4a52c2442ff3edd5e64d47480735 · sha256:b98cd41a522447fd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.