GHSA-53gr-wmf4-8hh3 · Severity: low · Ecosystem: rust — uutils coreutils's User Interface (UI) Misrepresents Critical Information
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control.
Conclusion & alert: CVE-2026-35371 is rated Exploit Available (50/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.01%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-23 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.3 | 3.1 | LOW |
|
1.8 | 1.4 | [email protected] |
GHSA-53gr-wmf4-8hh3 · Severity: low · Ecosystem: rust — uutils coreutils's User Interface (UI) Misrepresents Critical Information
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-35371 not yet assigned priority: Debian including 1 source packages (rust-coreutils), 3 status rows across 3 suites (bookworm, sid, trixie): open 3. | https://security-tracker.debian.org/tracker/CVE-2026-35371 |
ubuntu
|
medium | CVE-2026-35371 medium priority: Ubuntu including 1 source packages (rust-coreutils), 5 status rows across 5 suites (jammy, noble, questing, resolute, upstream): needed 4, DNE 1. | https://ubuntu.com/security/CVE-2026-35371 |
| URL | Tags |
|---|---|
| https://github.com/uutils/coreutils/issues/10006 | Exploit Issue Tracking |