uu_mknod
Cross-platform Rust rewrite of the GNU coreutils
Activity
- Latest release
- 1w ago
- Total releases
- 40
- Cadence
- ~2 months
- Last 12 months
- 9
Reach
- Stars
- 24.0k
Details
- License
- MIT
- First release
- May 31, 2020
| Version | Released | |
|---|---|---|
0.11.0
minor
| ||
0.10.0
minor
| ||
0.9.0
unknown
| ||
0.8.0
unknown
| ||
0.7.0
unknown
| ||
0.6.0
unknown
| ||
0.5.0
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.4.0
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.3.0
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.2
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.0
unknown
yanked
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.1.0
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.30
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.29
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.28
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.27
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.26
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.25
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.24
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.23
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.22
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.21
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.20
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.19
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.18
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.17
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.16
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.15
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.14
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.13
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.12
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.9
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.8
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.7
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.6
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.5
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.4
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.3
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.2
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.1
unknown
1 CVE
CVE-2026-35361
GHSA-r9hw-mj3w-phcq
Jul 06, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
3.4
/ 10
Low
Local
Low
High
None
Unchanged
Low
Low
None
uutils calls Impact: on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use Remediation: Acknowledged by Canonical. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev |