Your message dated Fri, 7 Aug 2026 09:21:58 +0200
with message-id <[email protected]>
and subject line Re: [Pkg-rust-maintainers] Bug#1135994: closed by Sylvestre
Ledru <[email protected]> (rust-coreutils: CVE fixes landed)
has caused the Debian Bug report #1135994,
regarding rust-coreutils: CVE-2026-35345
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1135994: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1135994
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rust-coreutils
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for rust-coreutils.
CVE-2026-35345[0]:
| A vulnerability in the tail utility of uutils coreutils allows for
| the exfiltration of sensitive file contents when using the
| --follow=name option. Unlike GNU tail, the uutils implementation
| continues to monitor a path after it has been replaced by a symbolic
| link, subsequently outputting the contents of the link's target. In
| environments where a privileged user (e.g., root) monitors a log
| directory, a local attacker with write access to that directory can
| replace a log file with a symlink to a sensitive system file (such
| as /etc/shadow), causing tail to disclose the contents of the
| sensitive file.
https://github.com/uutils/coreutils/issues/10328
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-35345
https://www.cve.org/CVERecord?id=CVE-2026-35345
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Hi Salvatore,
The fix did land in 0.10.0, just not via issue #10328, which wasn't closed:
it went in as PR #12661 (commit 2c2f1b0c1, merged 2026-07-05, before the
0.10.0 tag).
Cheers,
Sylvestre
Le 07/08/2026 à 05:49, Salvatore Bonaccorso a écrit :
Hi Sylvestre,
It looks the fix for ttps://github.com/uutils/coreutils/issues/10328
did not reach though the 0.10.0 upstream version, can you check?
Regards,
Salvatore
_______________________________________________
Pkg-rust-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-rust-maintainers
--- End Message ---