Bug 2460796 (CVE-2026-35354) - CVE-2026-35354 rust-coreutils: uutils coreutils mv utility: Privilege escalation via TOCTOU vulnerability during cross-device moves
Summary: CVE-2026-35354 rust-coreutils: uutils coreutils mv utility: Privilege escalat...
Keywords:
Status: NEW
Alias: CVE-2026-35354
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2463768 2463769
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-22 17:03 UTC by OSIDB Bzimport
Modified: 2026-07-18 08:28 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-22 17:03:10 UTC
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device moves. The extended attribute (xattr) preservation logic uses multiple path-based system calls that perform fresh path-to-inode lookups for each operation. A local attacker with write access to the directory can exploit this race to swap files between calls, causing the destination file to receive an inconsistent mix of security xattrs, such as SELinux labels or file capabilities.


Note You need to log in before you can comment on or make changes to this bug.