Executive brief
The mknod utility in uutils coreutils, a Rust-based implementation of standard system tools, fails to correctly handle security labels when creating device nodes. If the utility fails to set the required security context (SELinux), it leaves behind a mislabeled file that it cannot automatically clean up. This could allow unauthorized users or processes to access sensitive device nodes that should have been restricted by system security policies.
Technical details
The mknod utility in uutils coreutils (Rust implementation) fails to handle security labels atomically by creating device nodes before setting the SELinux context. If the labeling step fails, the utility attempts to clean up the created node using 'std::fs::remove_dir', which is ineffective against device nodes or FIFOs. This results in the persistence of mislabeled nodes with incorrect default contexts. A local attacker with high privileges could potentially exploit this to bypass mandatory access controls (MAC) on restricted device nodes. The issue is fixed in version 0.6.0 by replacing the cleanup logic with 'std::fs::remove_file'.
Affected products
- uutils coreutils (Rust) < 0.6.0
Timeline
- 2026-01-30: other: Fix submitted via pull request #10582
- 2026-02-02: patched: Version 0.6.0 released
- 2026-04-22: advisory: Initial GHSA and NVD publication
- 2026-07-06: other: Advisory withdrawn as duplicate of GHSA-r9hw-mj3w-phcq