CVE-2026-35379: uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling

Published Apr 22, 2026
·
Updated

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:] class and excludes it from the [:print:] class, effectively reversing the standard behavior established by POSIX and GNU coreutils. This vulnerability leads to unintended data modification or loss when the utility is used in automated scripts or data-cleaning pipelines that rely on standard character class semantics. For example, a command executed to delete all graphical characters while intending to preserve whitespace will incorrectly delete all ASCII spaces, potentially resulting in data corruption or logic failures in downstream processing.

Affected Software

2 affected components
uutils uutils coreutils
uutils Coreutils Rust<0.8.0

Event History

Apr 22, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35379?

CVE-2026-35379 is classified as a logic error vulnerability in the uutils coreutils tr utility.

2

How do I fix CVE-2026-35379?

To fix CVE-2026-35379, update uutils coreutils to version 0.8.0 or later, which addresses the character class handling issue.

3

What are the potential impacts of CVE-2026-35379?

The potential impacts of CVE-2026-35379 include incorrect character class handling, leading to data integrity issues in processing text.

4

Which versions of uutils coreutils are affected by CVE-2026-35379?

CVE-2026-35379 affects versions of uutils coreutils prior to version 0.8.0.

5

Can CVE-2026-35379 lead to security breaches?

While primarily a logic error, CVE-2026-35379 could potentially allow for unexpected behavior in applications relying on the tr utility, which may lead to further security concerns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203