CVE Explorer
CVE-2026-35378
A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw prevents the utility from performing proper short-circuiting for logical OR (|) and AND (&) operations. As a result, arithmetic errors (such as division by zero) occurring within "dead" branches, branches that should be ignored due to short-circuiting, are raised as fatal errors. This divergence fro
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/uutils","defaultStatus":"unaffected","packageName":"coreutils","platforms":["Linux","Unix","macOS"],"product":"coreutils","repo":"https://github.com/uutils/coreutils","vendor":"Uutils","versions":[{"lessThan":"0.8.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6dfc5d1eaeb62fda39b1d2719eb4c67c675633b2b8b9f633ccd020226db67cbc · sha256:92542a223acdc326… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6dfc5d1eaeb62fda39b1d2719eb4c67c675633b2b8b9f633ccd020226db67cbc · sha256:92542a223acdc326… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-768","description":"CWE-768: Incorrect Short Circuit Evaluation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6dfc5d1eaeb62fda39b1d2719eb4c67c675633b2b8b9f633ccd020226db67cbc · sha256:92542a223acdc326… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["issue-tracking","patch"],"url":"https://github.com/uutils/coreutils/pull/11395"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6dfc5d1eaeb62fda39b1d2719eb4c67c675633b2b8b9f633ccd020226db67cbc · sha256:92542a223acdc326… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://github.com/uutils/coreutils/releases/tag/0.8.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6dfc5d1eaeb62fda39b1d2719eb4c67c675633b2b8b9f633ccd020226db67cbc · sha256:92542a223acdc326… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.