Junglewise Threat Intelligence

CVE-2026-35369: uutils coreutils improper input validation in kill utility

CVE-2026-35369 · Severity: medium · CVSS 5.5 · Published 2026-07-06

Vendors: crates.io, Uutils.

Executive brief

A vulnerability in the 'kill' utility of the uutils coreutils package (a Rust-based alternative to standard Linux system tools) can cause an accidental or intentional system crash. When a user types a specific command intended to specify a signal, the tool incorrectly interprets it as a command to terminate every single process the user has permission to see. This can lead to immediate service outages, data loss from unsaved work, or a complete system shutdown.

Technical details

An argument parsing error in the 'uu_kill' component of uutils coreutils incorrectly interprets the command 'kill -1' as a request to send the default SIGTERM signal to PID -1. In Unix-like systems, sending a signal to PID -1 is a broadcast operation that targets every process the caller has permission to signal. This behavior deviates from the standard GNU coreutils implementation, which correctly identifies '-1' as a signal number and errors out due to a missing PID. A local attacker or an uninformed user can trigger this to cause a Denial of Service (DoS) by mass-terminating processes. The issue is fixed in version 0.6.0 by ensuring '-N' is parsed as a signal and validating that a PID is provided.

Affected products

  • uutils coreutils (uu_kill) < 0.6.0

Timeline

  • 2025-12-19: patched: Fix merged into main branch via commit 2d3aebc
  • 2026-01-20: disclosed: Reported by Zellic during security assessment for Canonical
  • 2026-02-02: other: Version 0.6.0 released containing the fix
  • 2026-07-06: advisory: GitHub Advisory published

References