CVE-2026-35376: uutils coreutils chcon Security Bypass and Mandatory Access Control (MAC) Inconsistency via TOCTOU Race Condition

Published Apr 22, 2026
·
Updated

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive operations. The implementation resolves recursive targets using a fresh path lookup (via ftsaccpath) rather than binding the traversal and label application to the specific directory state encountered during traversal. Because these operations are not anchored to file descriptors, a local attacker with write access to a directory tree can exploit timing-sensitive rename or symbolic link races to redirect a privileged recursive relabeling operation to unintended files or directories. This vulnerability breaks the hardening expectations for SELinux administration workflows and can lead to the unauthorized modification of security labels on sensitive system objects.

Affected Software

2 affected components
uutils uutils coreutils chcon
uutils Coreutils Rust<0.8.0

Event History

Apr 22, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35376?

CVE-2026-35376 is identified as a security bypass vulnerability that may allow unauthorized access due to a TOCTOU race condition.

2

How do I fix CVE-2026-35376?

To mitigate CVE-2026-35376, update to the latest version of uutils coreutils where the vulnerability has been addressed.

3

Which software is affected by CVE-2026-35376?

CVE-2026-35376 affects the chcon utility within uutils coreutils during recursive operations.

4

What is the impact of CVE-2026-35376?

The impact of CVE-2026-35376 includes a potential bypass of Mandatory Access Control, leading to privilege escalations.

5

Is there a workaround for CVE-2026-35376?

A recommended workaround for CVE-2026-35376 is to avoid using the chcon utility for recursive operations until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203