Group Miscalculation Vulnerability in Uutils Coreutils
CVE-2026-35370

4.4MEDIUM

Key Information:

Vendor

Uutils

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-35370?

The id utility in Uutils Coreutils has a critical flaw that affects how it computes group information. By using a user's real GID instead of their effective GID, it produces output that can differ significantly from that of GNU Coreutils. This inconsistency may disrupt automated scripts and processes which depend on accurate group data for making security-critical access control decisions. Such discrepancies can lead to unauthorized access or misconfigurations, thereby compromising system security.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zellic
.