GHSA-q94g-3gcf-66x7

Suggest an improvement
Source
https://github.com/advisories/GHSA-q94g-3gcf-66x7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q94g-3gcf-66x7/GHSA-q94g-3gcf-66x7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q94g-3gcf-66x7
Aliases
  • CVE-2026-35370
Related
Withdrawn
2026-07-06T20:16:40Z
Published
2026-04-22T18:31:46Z
Modified
2026-07-06T20:31:27.400355337Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Duplicate Advisory: uutils coreutils has an Incorrect Authorization issue
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-47c7-qrm7-mqw7. This link is maintained to preserve external references.

Original Description

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "MODERATE",
    "nvd_published_at": "2026-04-22T17:16:40Z",
    "github_reviewed_at": "2026-04-30T17:51:17Z"
}
References

Affected packages

crates.io / coreutils

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q94g-3gcf-66x7/GHSA-q94g-3gcf-66x7.json"