Logic Error in Uutils Coreutils Cut Utility Affects Data Processing
CVE-2026-35380

5.5MEDIUM

Key Information:

Vendor

Uutils

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-35380?

A logic error in the cut utility of Uutils Coreutils may cause the program to misinterpret a two-byte string as an empty delimiter. This issue leads to incorrect data processing, where NUL characters are used in place of intended literal characters. Automated scripts and data pipelines that handle strings could experience silent data corruption or unexpected behavior as the utility erroneously manipulates data.

Affected Version(s)

coreutils Linux 0 < 0.8.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zellic
.