Executive brief
A vulnerability in the uutils coreutils 'mkfifo' utility allows a local user to unintentionally modify the permissions of existing files. If a user attempts to create a special file (FIFO) where a file already exists, the utility may reset that existing file's permissions to a default state. This could lead to sensitive data, such as private encryption keys or system configuration files, becoming readable by unauthorized users on the same system.
Technical details
A vulnerability exists in the uutils coreutils implementation of mkfifo (CWE-732). When mkfifo attempts to create a FIFO at a path where a file already exists, the creation fails, but the program continues to execute a follow-up 'set_permissions' call on that path. This results in the existing file's permissions being reset to the default mode (typically 0644 adjusted by umask). A local attacker can exploit this behavior, or a related TOCTOU race condition involving symlinks, to modify the permissions of sensitive files they do not own, potentially leading to unauthorized data access. The issue affects uutils coreutils versions up to and including 0.8.0.
Affected products
- uutils coreutils <= 0.8.0
Timeline
- 2026-01-03: disclosed: Issue reported on GitHub repository
- 2026-04-22: advisory: Initial GHSA and NVD publication
- 2026-07-06: other: Advisory withdrawn as a duplicate of GHSA-pmf6-rcx4-v53v