CVE-2026-35380: uutils coreutils cut Local Logic Error and Data Integrity Issue in Delimiter Parsing

Published Apr 22, 2026
·
Updated

A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as an empty delimiter. The implementation mistakenly maps this string to the NUL character for both the -d (delimiter) and --output-delimiter options. This vulnerability can lead to silent data corruption or logic errors in automated scripts and data pipelines that process strings containing these characters, as the utility may unintentionally split or join data on NUL bytes rather than the intended literal characters.

Affected Software

2 affected components
uutils uutils coreutils
uutils Coreutils Rust<0.8.0

Event History

Apr 22, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35380?

CVE-2026-35380 is classified as a local logic error and data integrity issue that affects the delimiter parsing in the uutils coreutils cut utility.

2

How do I fix CVE-2026-35380?

To fix CVE-2026-35380, update to the latest version of uutils coreutils that addresses this logic error.

3

What are the potential impacts of CVE-2026-35380?

CVE-2026-35380 may lead to incorrect interpretations of delimiter inputs, potentially compromising data integrity.

4

Which versions of uutils coreutils are affected by CVE-2026-35380?

CVE-2026-35380 affects versions of uutils coreutils prior to the fix included in release 0.8.0.

5

Is CVE-2026-35380 exploitable by local users?

Yes, CVE-2026-35380 can be exploited by local users who utilize the cut utility with improperly formatted delimiters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203