Executive brief
A vulnerability in the 'kill' utility of the uutils coreutils package (a Rust-based alternative to standard Linux system tools) can cause an accidental or intentional system crash. When a user types a specific command intended to specify a signal, the tool incorrectly interprets it as a command to terminate every single process the user has permission to see. This can lead to immediate service outages, data loss from unsaved work, or a complete system shutdown.
Technical details
An argument parsing error in the 'uu_kill' component of uutils coreutils incorrectly interprets the command 'kill -1' as a request to send the default SIGTERM signal to PID -1. In Unix-like systems, sending a signal to PID -1 is a broadcast operation that targets every process the caller has permission to signal. This behavior deviates from the standard GNU coreutils implementation, which correctly identifies '-1' as a signal number and errors out due to a missing PID. A local attacker or an uninformed user can trigger this to cause a Denial of Service (DoS) by mass-terminating processes. The issue is fixed in version 0.6.0 by ensuring '-N' is parsed as a signal and validating that a PID is provided.
Affected products
- uutils coreutils (uu_kill) < 0.6.0
Timeline
- 2025-12-19: patched: Fix merged into main branch via commit 2d3aebc
- 2026-01-20: disclosed: Reported by Zellic during security assessment for Canonical
- 2026-02-02: other: Version 0.6.0 released containing the fix
- 2026-07-06: advisory: GitHub Advisory published
References
- https://github.com/uutils/coreutils/security/advisories/GHSA-p6rv-2qpm-fwvg
- https://github.com/uutils/coreutils/pull/9700
- https://github.com/uutils/coreutils/commit/2d3aebce6712841bc08b9b94e9078be50a25fc10
- https://github.com/uutils/coreutils/releases/tag/0.6.0
- https://api.github.com/repos/uutils/coreutils/security-advisories/GHSA-p6rv-2qpm-fwvg