uu_id
Cross-platform Rust rewrite of the GNU coreutils
Activity
- Latest release
- 1w ago
- Total releases
- 40
- Cadence
- ~2 months
- Last 12 months
- 9
Reach
- Stars
- 24.0k
Details
- License
- MIT
- First release
- May 31, 2020
| Version | Released | |
|---|---|---|
0.11.0
minor
| ||
0.10.0
minor
| ||
0.9.0
unknown
| ||
0.8.0
unknown
| ||
0.7.0
unknown
| ||
0.6.0
unknown
| ||
0.5.0
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.4.0
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.3.0
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.2
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.0
unknown
yanked
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.1.0
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.30
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.29
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.28
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.27
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.26
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.25
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.24
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.23
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.22
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.21
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.20
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.19
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.18
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.17
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.16
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.15
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.14
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.13
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.12
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.9
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.8
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.7
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.6
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.5
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.4
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.3
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.2
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.1
unknown
2 CVEs
CVE-2026-35370
GHSA-47c7-qrm7-mqw7
Jul 06, 2026
id: groups= computed from real GID instead of effective GID
4.4
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
None
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations. Zellic finding 3.72. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev
CVE-2026-35371
GHSA-xv5w-cw7x-72gj
Jul 06, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
Low
None
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output that can cause automated scripts or system administrators to make incorrect decisions regarding file permissions or access control. Zellic finding 3.73. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References Updated Jul 06, 2026 · Source: OSV.dev |