Junglewise Threat Intelligence

CVE-2026-35370: uutils coreutils incorrect GID calculation in id utility

CVE-2026-35370 · Severity: medium · CVSS 4.4 · Published 2026-07-06

Vendors: crates.io.

Executive brief

The 'id' utility in uutils coreutils, a Rust-based alternative to standard Linux system tools, incorrectly reports a user's group memberships. It mistakenly uses a user's permanent identity (real GID) instead of their current active identity (effective GID) when generating output. This can cause automated security scripts to make incorrect decisions, potentially leading to unauthorized access or system misconfigurations.

Technical details

The vulnerability is classified as an incorrect authorization check (CWE-863) and improper check for dropped privileges (CWE-273) within the 'id' utility of uutils coreutils. The implementation incorrectly retrieves the group list based on the real Group ID (RGID) rather than the effective Group ID (EGID). An attacker with local access can exploit this by executing scripts or processes that rely on the output of 'id' to verify permissions, potentially bypassing intended access restrictions when effective privileges have been modified (e.g., via setpriv). The issue was identified in audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242 and is fixed in version 0.6.0.

Affected products

  • uutils coreutils uu_id < 0.6.0

Timeline

  • 2026-01-03: disclosed: Issue reported to uutils coreutils maintainers
  • 2026-05-30: patched: Version 0.6.0 released and advisory published on GitHub
  • 2026-07-06: advisory: GitHub Advisory reviewed and updated

References

Related threats