CVE-2026-35369: uutils coreutils kill System-wide Process Termination and Denial of Service via Argument Misinterpretation
kill -1 is incorrectly parsed as a positional pid = -1; combined with the default SIGTERM this calls kill(-1, SIGTERM), signaling nearly every process the caller can see. GNU kill recognizes -1/-9 as signals and reports "not enough arguments".
$ kill -1 # uutils: kill(-1, SIGTERM) -> mass termination / crash $ kill -1 # GNU: kill: not enough arguments
Impact: a user running kill -1 mass-terminates processes, potentially crashing the system. Recommendation: parse -N as a signal number, and error with "not enough arguments" when no PID is given.
Remediation: Acknowledged by Canonical; fixed in commit cae94028.
--- Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.70. Credit: Zellic.
Other sources
An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to PID -1. Sending a signal to PID -1 causes the kernel to terminate all processes visible to the caller, potentially leading to a system crash or massive process termination. This differs from GNU coreutils, which correctly recognizes -1 as a signal number in this context and would instead report a missing PID argument.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/uu_killto a version that resolves this vulnerability.Fixed in 0.6.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch cae94028 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 3a07ffc5a9bd4c283e75afa548ba1f1957bad242
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35369?
CVE-2026-35369 has a high severity due to its potential to cause a system-wide denial of service.
How do I fix CVE-2026-35369?
To fix CVE-2026-35369, update to the latest version of uutils coreutils that addresses this vulnerability.
What kind of vulnerabilities does CVE-2026-35369 have?
CVE-2026-35369 has vulnerabilities related to argument misinterpretation in the kill utility leading to unintended process termination.
What impact does CVE-2026-35369 have on system security?
CVE-2026-35369 can impact system security by allowing unauthorized termination of critical processes, potentially leading to denial of service.
Is CVE-2026-35369 a local or remote vulnerability?
CVE-2026-35369 is a local vulnerability as it involves improper command usage that affects processes on the same system.