CVE Explorer
CVE-2026-35371
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/uutils","defaultStatus":"affected","packageName":"coreutils","platforms":["Linux","Unix","macOS"],"product":"coreutils","repo":"https://github.com/uutils/coreutils","vendor":"Uutils"}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7a017a913ec6d0f722c15a11e628afd3b9ad3886fe249e6f03dcc5087235d81c · sha256:c6c8eedba5be3990… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7a017a913ec6d0f722c15a11e628afd3b9ad3886fe249e6f03dcc5087235d81c · sha256:c6c8eedba5be3990… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-451","description":"CWE-451: User Interface (UI) Misrepresentation of Critical Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7a017a913ec6d0f722c15a11e628afd3b9ad3886fe249e6f03dcc5087235d81c · sha256:c6c8eedba5be3990… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["issue-tracking"],"url":"https://github.com/uutils/coreutils/issues/10006"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7a017a913ec6d0f722c15a11e628afd3b9ad3886fe249e6f03dcc5087235d81c · sha256:c6c8eedba5be3990… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/uutils/coreutils/issues/10006"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7a017a913ec6d0f722c15a11e628afd3b9ad3886fe249e6f03dcc5087235d81c · sha256:c6c8eedba5be3990… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.