CVE-2026-35372: uutils coreutils ln Security Bypass via Improper Handling of the --no-dereference Flag

Published Apr 22, 2026
·
Updated

A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when the --no-dereference (or -n) flag is explicitly provided. The implementation previously only honored the "no-dereference" intent if the --force (overwrite) mode was also enabled. This flaw causes ln to follow a symbolic link that points to a directory and create new links inside that target directory instead of treating the symbolic link itself as the destination. In environments where a privileged user or system script uses ln -n to update a symlink, a local attacker could manipulate existing symbolic links to redirect file creation into sensitive directories, potentially leading to unauthorized file creation or system misconfiguration.

Affected Software

2 affected components
uutils uutils coreutils
uutils Coreutils Rust<0.8.0

Event History

Apr 22, 2026
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35372?

CVE-2026-35372 is classified as a security bypass vulnerability due to improper handling of the --no-dereference flag.

2

How do I fix CVE-2026-35372?

To address CVE-2026-35372, update to a patched version of uutils coreutils that resolves this logic error.

3

What software is affected by CVE-2026-35372?

CVE-2026-35372 affects the uutils coreutils package, specifically the ln utility.

4

What is the impact of CVE-2026-35372?

The impact of CVE-2026-35372 is that it allows symbolic links to be dereferenced despite the --no-dereference flag being set.

5

Is CVE-2026-35372 exploitable in its current state?

Yes, CVE-2026-35372 is exploitable, which could lead to unintended file modifications and potential security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203