Executive brief
A vulnerability in the Rust implementation of the 'rm' command-line utility could allow the accidental or intentional deletion of the entire system's root directory. The tool's safety feature designed to prevent deleting the root filesystem can be bypassed using symbolic links. This could lead to a total loss of system data and operating system functionality.
Technical details
A vulnerability in the 'rm' utility of uutils coreutils (the Rust implementation of GNU coreutils) allows a bypass of the '--preserve-root' protection. The root cause is that the implementation performed a path-string check (e.g., checking for '/') rather than comparing device and inode numbers to identify the actual root directory. An attacker or user can bypass this safeguard by using a symbolic link that resolves to the root directory (e.g., '/tmp/rootlink -> /'). If 'rm -rf --preserve-root /tmp/rootlink' is executed, the utility may proceed to delete the entire root filesystem. This issue is addressed in version 0.7.0 by properly resolving metadata before performing the safety check.
Affected products
- uutils coreutils (Rust) < 0.7.0
Timeline
- 2025-12-18: other: Initial pull request submitted
- 2026-02-05: patched: Fix merged into main branch
- 2026-03-08: advisory: Release 0.7.0 published
- 2026-04-22: disclosed: Vulnerability published to GitHub Advisory Database
- 2026-07-06: other: Advisory withdrawn as a duplicate of GHSA-7cr3-h577-g38j