UBUNTU-CVE-2026-35365

Source
https://ubuntu.com/security/CVE-2026-35365
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35365.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-35365
Upstream
  • CVE-2026-35365
Published
2026-04-22T17:16:00Z
Modified
2026-05-14T14:41:37.505773Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of preserving symlinks, the implementation expands them, copying the linked targets as real files or directories at the destination. This can lead to resource exhaustion (disk space or time) if symlinks point to large external directories, unexpected duplication of sensitive data into unintended locations, or infinite recursion and repeated copying in the presence of symlink loops.

References

Affected packages

Ubuntu:24.04:LTS / rust-coreutils

Package

Name
rust-coreutils
Purl
pkg:deb/ubuntu/rust-coreutils@0.0.24-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20-1
0.0.22-1
0.0.23-1
0.0.23-2
0.0.23-3
0.0.24-1
0.0.24-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.0.24-2",
            "binary_name": "rust-coreutils"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35365.json"

Ubuntu:25.10 / rust-coreutils

Package

Name
rust-coreutils
Purl
pkg:deb/ubuntu/rust-coreutils@0.2.2-0ubuntu2.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.30-1
0.0.30-2
0.0.30-2ubuntu2
0.1.0-0ubuntu1
0.1.0+git20250711.2ba3a33-0ubuntu1
0.1.0+git20250711.2ba3a33-0ubuntu2
0.1.0+git20250711.2ba3a33-0ubuntu3
0.1.0+git20250711.2ba3a33-0ubuntu4
0.1.0+git20250801.cf79675-0ubuntu1
0.1.0+git20250813.4af2a84-0ubuntu2
0.1.0+git20250813.4af2a84-0ubuntu4
0.1.0+git20250813.4af2a84-0ubuntu6
0.1.0+git20250813.4af2a84-0ubuntu7
0.2.2-0ubuntu1
0.2.2-0ubuntu2
0.2.2-0ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.2.2-0ubuntu2.1",
            "binary_name": "rust-coreutils"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35365.json"