Vulnerability record · CVE-2026-35358 · published 22 April 2026
CVE-2026-35358: Uutils coreutils vulnerability
UUutils · Coreutils
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.
Description
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/uutils/coreutils/issues/9746 | ExploitIssue Tracking |
| https://github.com/uutils/coreutils/pull/11163 | Issue TrackingPatch |
| https://github.com/uutils/coreutils/releases/tag/0.7.0 | Release Notes |
| https://github.com/uutils/coreutils/issues/9746 | ExploitIssue Tracking |
Track CVE-2026-35358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-35358), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.