#1135994 rust-coreutils: CVE-2026-35345

#1135994#5
Date:
2026-05-08 13:06:22 UTC
From:
To:
Hi,

The following vulnerability was published for rust-coreutils.

CVE-2026-35345[0]:
| A vulnerability in the tail utility of uutils coreutils allows for
| the exfiltration of sensitive file contents when using the
| --follow=name option. Unlike GNU tail, the uutils implementation
| continues to monitor a path after it has been replaced by a symbolic
| link, subsequently outputting the contents of the link's target. In
| environments where a privileged user (e.g., root) monitors a log
| directory, a local attacker with write access to that directory can
| replace a log file with a symlink to a sensitive system file (such
| as /etc/shadow), causing tail to disclose the contents of the
| sensitive file.

https://github.com/uutils/coreutils/issues/10328

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-35345
https://www.cve.org/CVERecord?id=CVE-2026-35345

Please adjust the affected versions in the BTS as needed.

#1135994#12
Date:
2026-08-06 21:57:47 UTC
From:
To:
These CVEs are all fixed in the upstream 0.10.0 release, which was
uploaded to unstable as rust-coreutils 0.10.0-1:

#1135993 CVE-2026-35344 dd: propagate truncate errors on regular files
#1135994 CVE-2026-35345 tail: treat a watched file replaced by a symlink
as untailable
#1136042 CVE-2026-35352 mkfifo: drop path-based chmod, closing the
TOCTOU race
#1136044 CVE-2026-35360 touch: create without O_TRUNC so a raced open no
longer truncates
#1136202 CVE-2026-35374 split: harden output open path against TOCTOU
target swaps
#1136203 CVE-2026-35376 chcon: anchor recursive relabel resolution to
the traversal dirfd
#1136207 CVE-2026-35377 env: keep backslashes literal in single quotes,
matching GNU

Cheers
Sylvestre

#1135994#17
Date:
2026-08-07 03:49:29 UTC
From:
To:
Hi Sylvestre,

It looks the fix for ttps://github.com/uutils/coreutils/issues/10328
did not reach though the 0.10.0 upstream version, can you check?

Regards,
Salvatore

#1135994#24
Date:
2026-08-07 07:21:58 UTC
From:
To:
Hi Salvatore,

The fix did land in 0.10.0, just not via issue #10328, which wasn't closed:
it went in as PR #12661 (commit 2c2f1b0c1, merged 2026-07-05, before the
0.10.0 tag).

Cheers,
Sylvestre

Le 07/08/2026 à 05:49, Salvatore Bonaccorso a écrit :

#1135994#29
Date:
2026-08-07 07:51:01 UTC
From:
To:
Hi Sylvestre,

Thanks, I will update our records accordingly.

Regards,
Salvatore

#1135994#34
Date:
2026-08-07 09:25:08 UTC
From:
To:
Impressive attention to details! :)
-------- Original Message -------- On Friday, 08/07/26 at 09:53 Salvatore Bonaccorso <carnil@debian.org> wrote: Hi Sylvestre, Thanks, I will update our records accordingly. Regards, Salvatore