GHSA-p6rv-2qpm-fwvg

Suggest an improvement
Source
https://github.com/advisories/GHSA-p6rv-2qpm-fwvg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p6rv-2qpm-fwvg/GHSA-p6rv-2qpm-fwvg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p6rv-2qpm-fwvg
Aliases
Published
2026-07-06T19:55:15Z
Modified
2026-07-06T20:11:15Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
Details

kill -1 is incorrectly parsed as a positional pid = -1; combined with the default SIGTERM this calls kill(-1, SIGTERM), signaling nearly every process the caller can see. GNU kill recognizes -1/-9 as signals and reports "not enough arguments".

$ kill -1        # uutils: kill(-1, SIGTERM) -> mass termination / crash
$ kill -1        # GNU: kill: not enough arguments

Impact: a user running kill -1 mass-terminates processes, potentially crashing the system. Recommendation: parse -N as a signal number, and error with "not enough arguments" when no PID is given.

Remediation: Acknowledged by Canonical; fixed in commit cae94028.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.70. Credit: Zellic.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-754"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-06T19:55:15Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / uu_kill

Package

Name
uu_kill
View open source insights on deps.dev
Purl
pkg:cargo/uu_kill

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p6rv-2qpm-fwvg/GHSA-p6rv-2qpm-fwvg.json"