Back

MEDIUM

uutils coreutils install Arbitrary File Overwrite via Symlink TOCTOU Race

Published Apr 22, 2026

Description

The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local attacker can exploit the window between the unlink and the subsequent creation to swap the path with a symbolic link, allowing them to redirect privileged writes to overwrite arbitrary system files.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Apr 22, 2026
Updated Apr 22, 2026
Reserved Apr 2, 2026
CISA Vulnrichment
Updated Apr 22, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-239G-2685-54X3