Search CVE reports


Toggle filters

1 – 10 of 68 results


CVE-2026-19079

Medium priority
Needs evaluation

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...

1 affected package

policycoreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
policycoreutils Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-56392

Medium priority
Needs evaluation

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap...

1 affected package

coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coreutils Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-56391

Medium priority
Needs evaluation

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly...

1 affected package

coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coreutils Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59677

Medium priority
Needs evaluation

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects...

2 affected packages

policycoreutils, selinux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
policycoreutils Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
selinux Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-35381

Medium priority
Vulnerable

A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The implementation incorrectly routes...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Not affected Vulnerable Not in release
Show less packages

CVE-2026-35380

Medium priority
Vulnerable

A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as an empty delimiter. The implementation mistakenly maps this string to the NUL...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Not affected Vulnerable Not in release
Show less packages

CVE-2026-35379

Medium priority
Vulnerable

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:]...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Not affected Vulnerable Not in release
Show less packages

CVE-2026-35378

Medium priority
Vulnerable

A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw prevents the utility...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Not affected Vulnerable Not in release
Show less packages

CVE-2026-35377

Medium priority
Vulnerable

A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In GNU env, backslashes within single quotes are treated literally (with...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Vulnerable Vulnerable Not in release
Show less packages

CVE-2026-35376

Medium priority
Vulnerable

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive operations. The implementation resolves recursive targets using a fresh path lookup (via fts_accpath) rather...

1 affected package

rust-coreutils

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-coreutils Not affected Vulnerable Not in release
Show less packages