Junglewise Threat Intelligence

CVE-2026-35338: uutils coreutils chmod --preserve-root bypass via non-canonical paths

CVE-2026-35338 · Severity: high · CVSS 7.3 · Published 2026-07-06

Vendors: Uutils, crates.io.

Executive brief

A vulnerability in the uutils version of the chmod utility allows users to bypass a safety feature designed to protect the system's root directory. The '--preserve-root' flag, which is meant to prevent accidental or malicious deletion of system-wide file permissions, can be circumvented by using alternative path names like '/../'. If exploited, this could lead to a complete system breakdown as critical file permissions across the entire operating system are altered.

Technical details

A path traversal and link following vulnerability exists in the Chmoder::chmod() function of uutils coreutils. The implementation only performs a literal string comparison of the input path against '/' when the --preserve-root flag is active, failing to account for path canonicalization. An attacker with local access can provide a path that resolves to root (such as '/../' or a symlink to '/') to bypass this check. When combined with the recursive (-R) flag, this allows for destructive permission changes across the entire filesystem. The issue is fixed in version 0.6.0 by ensuring the target path is canonicalized before the root check.

Affected products

  • uutils coreutils (uu_chmod) < 0.6.0

Timeline

  • 2026-01-03: patched: Initial fix and regression tests submitted via PR #10033
  • 2026-01-07: patched: Fix merged into main branch
  • 2026-01-20: disclosed: Reported by Zellic in security assessment for Canonical
  • 2026-04-22: advisory: CVE-2026-35338 assigned and published to NVD
  • 2026-07-06: advisory: GitHub Advisory GHSA-4c7q-4928-8445 published

References

Related threats