GHSA-47c7-qrm7-mqw7

Suggest an improvement
Source
https://github.com/advisories/GHSA-47c7-qrm7-mqw7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-47c7-qrm7-mqw7/GHSA-47c7-qrm7-mqw7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-47c7-qrm7-mqw7
Aliases
  • CVE-2026-35370
Published
2026-07-06T20:16:46Z
Modified
2026-07-06T20:31:25.500970839Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
id: groups= computed from real GID instead of effective GID
Details

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.


Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-273",
        "CWE-863"
    ],
    "github_reviewed_at": "2026-07-06T20:16:46Z",
    "github_reviewed": true,
    "severity": "MODERATE"
}
References

Affected packages

crates.io / uu_id

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-47c7-qrm7-mqw7/GHSA-47c7-qrm7-mqw7.json"