CVE-2026-93658: uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

Published Sep 18, 2026
·
Updated

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.

Affected Software

1 affected component
uutils coreutils<0.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade uutils coreutils to a version that resolves this vulnerability.

    Fixed in 0.10.0
  2. Compensating control

    On capability-restricted systems, prevent execution of unexpected setuid/setgid binaries (e.g., remove/disable setuid and setgid permissions from uutils coreutils installation destinations where applicable) until ownership-change operations are reliable after upgrading to 0.10.0.

Event History

Sep 18, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems using uutils coreutils versions before 0.10.0 are exposed when privileged users install files with setuid or setgid modes and the intended ownership change can fail. The described attack condition specifically involves capability-restricted systems.

2

What does an attacker need to exploit it?

An attacker needs a leftover setuid executable whose ownership change failed during installation. They can then execute that file to obtain the elevated privileges associated with its privileged owner.

3

Are default installations necessarily affected?

The issue requires an installation operation that applies setuid or setgid mode and then encounters a failed ownership change. The provided information does not establish that this occurs in a default configuration.

4

What should be done if upgrading is not immediately possible?

Avoid installation workflows that create setuid or setgid destinations where ownership changes may fail, particularly on capability-restricted systems. Check for and remove or correct ownership and permission settings on any leftover setuid executables created by privileged installation operations.

5

How can I determine whether I may already be affected?

Review privileged installation operations for failed ownership changes and inspect resulting destination files for setuid or setgid permissions combined with ownership by the privileged invoker. Focus on installations performed with uutils coreutils versions before 0.10.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203