Executive brief
The 'install' utility in the uutils coreutils package (a Rust-based alternative to standard Linux command-line tools) contains a flaw in how it handles file replacements. A local attacker can exploit a brief timing window during the installation process to trick the utility into overwriting sensitive system files instead of the intended target. This could allow an attacker to gain elevated privileges or cause system instability by corrupting critical files like password databases.
Technical details
A TOCTOU symlink race exists in `copy_file` within `install/src/install.rs`. The utility unlinks a destination file and subsequently recreates it using path-based operations (`File::create` / `fs::copy`) without the `O_EXCL` flag. A local attacker with write access to the destination directory can insert a symbolic link during the window between the unlink and the recreation. If the `install` process is running with elevated privileges (e.g., during a system build or staging process), the write is redirected to the symlink target, enabling the overwrite of arbitrary files such as `/etc/passwd`. The vulnerability is fixed in version 0.6.0 by using atomic file creation with `O_EXCL`.
Affected products
- uutils uu_install < 0.6.0
Timeline
- 2026-01-05: other: Pull request submitted to fix the vulnerability
- 2026-01-17: patched: Fix merged into main branch
- 2026-01-20: disclosed: Security assessment report prepared by Zellic
- 2026-05-30: advisory: Initial advisory publication
- 2026-07-06: other: Advisory updated and published to GitHub Advisory Database
References
- https://github.com/uutils/coreutils/security/advisories/GHSA-239g-2685-54x3
- https://github.com/uutils/coreutils/pull/10067
- https://github.com/uutils/coreutils/commit/b5bbabc18a1121908848d836f869a4e98eb63886
- https://github.com/uutils/coreutils/releases/tag/0.6.0
- https://api.github.com/repos/uutils/coreutils/security-advisories/GHSA-239g-2685-54x3