Executive brief
A vulnerability in the uutils version of the chmod utility allows users to bypass a safety feature designed to protect the system's root directory. The '--preserve-root' flag, which is meant to prevent accidental or malicious deletion of system-wide file permissions, can be circumvented by using alternative path names like '/../'. If exploited, this could lead to a complete system breakdown as critical file permissions across the entire operating system are altered.
Technical details
A path traversal and link following vulnerability exists in the Chmoder::chmod() function of uutils coreutils. The implementation only performs a literal string comparison of the input path against '/' when the --preserve-root flag is active, failing to account for path canonicalization. An attacker with local access can provide a path that resolves to root (such as '/../' or a symlink to '/') to bypass this check. When combined with the recursive (-R) flag, this allows for destructive permission changes across the entire filesystem. The issue is fixed in version 0.6.0 by ensuring the target path is canonicalized before the root check.
Affected products
- uutils coreutils (uu_chmod) < 0.6.0
Timeline
- 2026-01-03: patched: Initial fix and regression tests submitted via PR #10033
- 2026-01-07: patched: Fix merged into main branch
- 2026-01-20: disclosed: Reported by Zellic in security assessment for Canonical
- 2026-04-22: advisory: CVE-2026-35338 assigned and published to NVD
- 2026-07-06: advisory: GitHub Advisory GHSA-4c7q-4928-8445 published
References
- https://github.com/uutils/coreutils/security/advisories/GHSA-4c7q-4928-8445
- https://github.com/uutils/coreutils/pull/10033
- https://github.com/uutils/coreutils/commit/413055b378fa6fe2299c5e5f538c8e6e841ab810
- https://github.com/uutils/coreutils/releases/tag/0.6.0
- https://api.github.com/repos/uutils/coreutils/security-advisories/GHSA-4c7q-4928-8445