{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3auutilscoreutils/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:uutils:coreutils:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-93658"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["coreutils (\u003c 0.10.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","linux"],"_cs_type":"advisory","_cs_vendors":["uutils"],"content_html":"\u003cp\u003eThe uutils coreutils project, a Rust-based implementation of GNU coreutils, is affected by a privilege escalation vulnerability (CVE-2026-93658) in versions prior to 0.10.0. The 'install' utility implementation incorrectly sequences the application of setuid and setgid bits relative to the ownership change operation. Specifically, the utility applies these permission bits before verifying the success of the chown operation. In environments with capability restrictions or file system constraints where ownership changes are prone to failure, an attacker can manipulate the process to ensure ownership changes fail, resulting in a setuid executable being created that is still owned by the privileged user who invoked the 'install' command. This allows an attacker to execute the leftover file with elevated privileges. This flaw impacts systems where uutils 'install' is used as part of deployment or build processes executed by privileged accounts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to execute arbitrary code with the privileges of the user running the 'install' command, typically root or a high-privileged service account. This could lead to full system compromise in environments where automated installation scripts are frequently used.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade uutils coreutils to version 0.10.0 or later immediately to address the insecure sequencing of permission and ownership operations.\u003c/li\u003e\n\u003cli\u003eAudit automation scripts or deployment pipelines that utilize the 'install' utility to determine if they are running in environments prone to ownership change failures, such as those with restricted Linux capabilities or specific file system mounting options (e.g., nosuid or restricted user namespaces).\u003c/li\u003e\n\u003cli\u003eImplement monitoring for the creation of new setuid or setgid binaries in system directories, particularly those following automated deployment or installation activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T16:09:02Z","date_published":"2026-09-18T16:09:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93658/","summary":"uutils coreutils versions before 0.10.0 are vulnerable to local privilege escalation due to an race condition in the install utility that preserves setuid/setgid bits when ownership changes fail.","title":"Privilege Escalation in uutils coreutils via Incorrect File Ownership Handling","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93658/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:uutils:coreutils:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}