Your message dated Thu, 6 Aug 2026 23:57:47 +0200
with message-id <[email protected]>
and subject line rust-coreutils: CVE fixes landed
has caused the Debian Bug report #1136203,
regarding rust-coreutils: CVE-2026-35376
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1136203: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136203
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rust-coreutils
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for rust-coreutils.
CVE-2026-35376[0]:
| A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the
| chcon utility of uutils coreutils during recursive operations. The
| implementation resolves recursive targets using a fresh path lookup
| (via fts_accpath) rather than binding the traversal and label
| application to the specific directory state encountered during
| traversal. Because these operations are not anchored to file
| descriptors, a local attacker with write access to a directory tree
| can exploit timing-sensitive rename or symbolic link races to
| redirect a privileged recursive relabeling operation to unintended
| files or directories. This vulnerability breaks the hardening
| expectations for SELinux administration workflows and can lead to
| the unauthorized modification of security labels on sensitive system
| objects.
https://github.com/uutils/coreutils/pull/11402
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-35376
https://www.cve.org/CVERecord?id=CVE-2026-35376
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Version: 0.10.0-1
These CVEs are all fixed in the upstream 0.10.0 release, which was
uploaded to unstable as rust-coreutils 0.10.0-1:
#1135993 CVE-2026-35344 dd: propagate truncate errors on regular files
#1135994 CVE-2026-35345 tail: treat a watched file replaced by a symlink
as untailable
#1136042 CVE-2026-35352 mkfifo: drop path-based chmod, closing the
TOCTOU race
#1136044 CVE-2026-35360 touch: create without O_TRUNC so a raced open no
longer truncates
#1136202 CVE-2026-35374 split: harden output open path against TOCTOU
target swaps
#1136203 CVE-2026-35376 chcon: anchor recursive relabel resolution to
the traversal dirfd
#1136207 CVE-2026-35377 env: keep backslashes literal in single quotes,
matching GNU
Cheers
Sylvestre
--- End Message ---