Description
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
Published: 2026-09-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via setuid bit mismanagement
Action: Apply Patch
AI Analysis

Impact

The issue appears in uutils coreutils versions earlier than 0.10.0. During installation the routine sets the setuid or setgid bit on destination files before attempting to modify ownership. When the ownership change fails, the setuid bit remains, leaving a privileged executable owned by the original invoker. An attacker who can induce such a failure may run the leftover binary with elevated privileges, effectively gaining higher rights than intended.

Affected Systems

This flaw affects the uutils coreutils package. It applies to any installation performed with 'install' from a pre‑0.10.0 release. The impact is specific to systems where the install command is run by a user who has write permissions to target directories and can trigger ownership‑change failures on capability‑restricted setups.

Risk and Exploitability

The CVSS score of 7.3 indicates a serious security risk. The EPSS score is < 1%, suggesting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access: the attacker must invoke the install routine, cause an ownership‑change failure, and then execute the lingering setuid binary. Successful exploitation results in full privilege escalation on the affected system.

Generated by OpenCVE AI on September 23, 2026 at 14:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade uutils coreutils to version 0.10.0 or newer which corrects the permission handling.
  • If an immediate upgrade is not possible, modify the installation scripts so that the setuid or setgid bit is applied only after a successful ownership change, or otherwise disable setuid on the installed files.
  • Verify that ownership modifications succeed before setting permissions and handle any errors to prevent dangling privileged executables.

Generated by OpenCVE AI on September 23, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-279
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
Title uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid
First Time appeared Uutils
Uutils coreutils
Weaknesses CWE-281
CPEs cpe:2.3:a:uutils:coreutils:*:*:*:*:*:*:*:*
Vendors & Products Uutils
Uutils coreutils
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Uutils Coreutils
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T16:48:03.334Z

Reserved: 2026-09-18T13:30:25.933Z

Link: CVE-2026-93658

cve-icon Vulnrichment

Updated: 2026-09-18T16:47:56.616Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:22.360

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93658

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T14:23:20Z

Links: CVE-2026-93658 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:15:06Z

Weaknesses
  • CWE-279

    Incorrect Execution-Assigned Permissions

  • CWE-281

    Improper Preservation of Permissions