GHSA-4x34-chg5-mwjj

Suggest an improvement
Source
https://github.com/advisories/GHSA-4x34-chg5-mwjj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4x34-chg5-mwjj/GHSA-4x34-chg5-mwjj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4x34-chg5-mwjj
Aliases
Published
2026-07-06T19:27:41Z
Modified
2026-07-06T19:41:24Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
Details

In Chmoder::chmod() the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the last file processed:

if self.recursive {
    r = self.walk_dir_with_context(file, true);   // overwrites r
} else {
    r = self.chmod_file(file).and(r);
}

PoC: GNU returns 1 when a file fails; uutils returns 0 if the last entry succeeds:

$ chmod -R 0755 chmod-bug/root chmod-bug/user  # GNU -> ret=1
$ uutils chmod -R 0755 chmod-bug/root chmod-bug/user  # -> ret=0

Impact: scripts relying on the exit code get a false success signal while some files retained restrictive/unexpected permissions, leading to access-control misconfigurations. Recommendation: accumulate errors during traversal.

Remediation: Acknowledged by Canonical; fixed in commit abd581f6.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.2. Credit: Zellic.

Database specific
{
    "cwe_ids":  [
        "CWE-252",
        "CWE-253",
        "CWE-755"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-06T19:27:41Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / uu_chmod

Package

Name
uu_chmod
View open source insights on deps.dev
Purl
pkg:cargo/uu_chmod

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4x34-chg5-mwjj/GHSA-4x34-chg5-mwjj.json"