Junglewise Threat Intelligence

CVE-2026-93658: uutils coreutils privilege escalation via setuid installation race

CVE-2026-93658 · Severity: high · CVSS 7 · Published 2026-09-18

Vendors: Uutils.

Executive brief

uutils coreutils is a Rust rewrite of the GNU coreutils utilities used in Unix-like systems. Versions before 0.10.0 contain a vulnerability where the install operation sets setuid/setgid permissions on files before finalizing ownership changes. If ownership changes fail (particularly on systems with Linux capabilities restrictions), this can leave executable files with elevated privileges owned by the invoker, allowing local privilege escalation.

Technical details

The vulnerability is a privilege escalation flaw in the install operation of uutils coreutils (versions before 0.10.0). The root cause is that setuid/setgid mode bits are applied to destination files before ownership changes are finalized; if the subsequent chown operation fails due to capability restrictions, the setuid executable remains owned by the invoker with elevated privileges intact. An attacker with local access and the ability to invoke install operations can exploit this race condition to execute setuid files with elevated privileges. The fix is available in version 0.10.0 and later, which reorders these operations to apply mode bits only after ownership is successfully changed.

Affected products

  • uutils coreutils before 0.10.0

Timeline

  • 2026-09-18: disclosed

References