Executive brief
The printenv utility in uutils coreutils, a Rust-based implementation of standard system tools, fails to display environment variables that contain invalid UTF-8 characters. This allows a local attacker to hide malicious environment settings, such as those used to hijack software libraries (LD_PRELOAD), from administrators and security auditing tools. While the system remains functional, security monitoring may fail to detect unauthorized changes to the environment.
Technical details
The printenv utility in uutils coreutils (uu_printenv) incorrectly uses Rust's env::var() and env::vars() functions, which silently skip environment variables that are not valid UTF-8. According to POSIX standards, environment variables can contain arbitrary byte sequences. An attacker with local access can craft environment variables (e.g., LD_PRELOAD) containing invalid UTF-8 bytes to ensure they are hidden from administrators or automated security scanners using printenv. This issue was resolved in version 0.6.0 by switching to the _os() variants of the environment functions to handle raw byte sequences.
Affected products
- uutils coreutils (uu_printenv) < 0.6.0
Timeline
- 2025-12-18: disclosed: Issue reported to uutils coreutils maintainers
- 2025-12-22: patched: Fix merged into main branch
- 2026-05-30: advisory: Initial advisory published by maintainers
- 2026-07-06: advisory: GitHub Advisory published
References
- https://github.com/uutils/coreutils/security/advisories/GHSA-p7h3-7q52-72w8
- https://github.com/uutils/coreutils/issues/9701
- https://github.com/uutils/coreutils/pull/9728
- https://github.com/uutils/coreutils/commit/0bfbbc00c7895c0fb6ea94987b4aab99e3d7ee52
- https://github.com/uutils/coreutils/releases/tag/0.6.0