Back

LOW

uutils coreutils split Local Data Integrity Issue via Lossy Filename Encoding

Published Apr 22, 2026

Description

A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The implementation utilizes to_string_lossy() when constructing chunk filenames, which automatically rewrites invalid byte sequences into the UTF-8 replacement character (U+FFFD). This behavior diverges from GNU split, which preserves raw pathname bytes intact. In environments utilizing non-UTF-8 encodings, this vulnerability leads to the creation of files with incorrect names, potentially causing filename collisions, broken automation, or the misdirection of output data.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Apr 22, 2026
Updated Apr 22, 2026
Reserved Apr 2, 2026
CISA Vulnrichment
Updated Apr 22, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner canonical
Published Apr 22, 2026
Updated Apr 22, 2026
Exploited since n/a
EUVD-2026-25026 GHSA-VX9M-XJWF-8CQM