Bug 2538898 (CVE-2026-93658)

Summary: CVE-2026-93658 rust-coreutils: uutils coreutils: Privilege Escalation via setuid/setgid handling
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in uutils coreutils. When installing files, the software applies `setuid` or `setgid` permissions before finalizing ownership changes. This can allow a privileged user to inadvertently leave behind executable files with elevated privileges if the ownership change operation fails on systems with restricted capabilities. A local attacker could then exploit these leftover files to achieve privilege escalation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539117, 2539118, 2539119    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 21:06:59 UTC
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.