Junglewise Threat Intelligence

uutils coreutils UI misrepresentation in id utility

Severity: low · CVSS 3.3 · Published 2026-04-22

Vendors: Uutils.

Executive brief

The 'id' utility in uutils coreutils, a Rust-based implementation of standard system tools, contains a bug that misreports user identity information. When a user's real and effective identities differ, the tool may display the wrong username or group details. This can lead system administrators or automated scripts to make incorrect security decisions regarding file permissions and access controls based on the misleading output.

Technical details

A vulnerability exists in the 'id' utility of uutils coreutils (Rust implementation) due to improper user interface representation of critical information (CWE-451). When the real UID and effective UID differ, the implementation incorrectly performs a name lookup for the effective user using the effective GID instead of the effective UID. This results in incorrect 'pretty print' and compact output. An attacker with local access can observe or potentially leverage this misrepresentation to deceive administrators or scripts that rely on 'id' output for access control logic. The issue affects versions up to and including 0.8.0.

Affected products

  • uutils coreutils (Rust) <= 0.8.0

Timeline

  • 2026-01-03: disclosed: Issue reported on GitHub repository
  • 2026-04-22: advisory: Initial advisory published
  • 2026-07-06: other: Advisory withdrawn as a duplicate of GHSA-xv5w-cw7x-72gj

References