GHSA-67hp-f6hq-2h6g

Suggest an improvement
Source
https://github.com/advisories/GHSA-67hp-f6hq-2h6g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-67hp-f6hq-2h6g/GHSA-67hp-f6hq-2h6g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-67hp-f6hq-2h6g
Withdrawn
2026-07-06T20:21:12Z
Published
2026-04-22T18:31:45Z
Modified
2026-09-10T03:50:43Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Duplicate Advisory: uutils coreutils Uses Incorrectly-Resolved Name or Reference
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8vrf-r662-2w2v. This link is maintained to preserve external references.

Original Description

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.

Database specific
{
    "cwe_ids":  [
        "CWE-706"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-30T17:13:35Z",
    "nvd_published_at":  "2026-04-22T17:16:38Z",
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / coreutils

Package

Name
coreutils
View open source insights on deps.dev
Purl
pkg:cargo/coreutils

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-67hp-f6hq-2h6g/GHSA-67hp-f6hq-2h6g.json"