Security Advisory

CVE-2026-35350

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-22 16:08:02
Last updated 2026-04-22 17:58:14
Assigner canonical
CVSS score 6.6
State PUBLISHED

Description

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved.