Executive brief
The 'mv' utility in uutils coreutils (a Rust-based alternative to standard Linux tools) contains a flaw when moving files between different storage drives or partitions. Instead of moving shortcuts (symbolic links) as they are, it incorrectly follows them and copies the actual data they point to. This can lead to a system running out of disk space, the accidental duplication of sensitive files into insecure locations, or the tool getting stuck in an infinite loop.
Technical details
A vulnerability exists in the uutils coreutils 'mv' implementation (uu_mv) due to improper link resolution (CWE-59) during cross-filesystem move operations. When a directory tree is moved across device boundaries, the utility dereferences symbolic links and copies the target content as new files/directories instead of recreating the symlink at the destination. A local attacker can exploit this by placing symlinks pointing to large files or sensitive system directories (like /etc) within a directory being moved, causing uncontrolled resource consumption (CWE-400) or unauthorized data duplication. The issue is fixed in version 0.7.0 by using symlink_metadata() to detect links and read_link()/symlink() to preserve them.
Affected products
- uutils coreutils (uu_mv) < 0.7.0
Timeline
- 2026-01-20: disclosed: Reported by Zellic in security assessment for Canonical
- 2026-03-05: patched: Fixed in commit 9654e4ab
- 2026-05-30: advisory: GitHub Advisory published
- 2026-07-06: other: Advisory reviewed and updated
References
- https://github.com/uutils/coreutils/security/advisories/GHSA-h444-6j9x-p8vh
- https://github.com/uutils/coreutils/pull/10546
- https://github.com/uutils/coreutils/commit/9654e4abaf24449ef2279e9a16963edb5c8b8fef
- https://github.com/uutils/coreutils/releases/tag/0.7.0
- https://api.github.com/repos/uutils/coreutils/security-advisories/GHSA-h444-6j9x-p8vh