uu_mv
Cross-platform Rust rewrite of the GNU coreutils
Activity
- Latest release
- 1w ago
- Total releases
- 40
- Cadence
- ~2 months
- Last 12 months
- 9
Reach
- Stars
- 24.0k
Details
- License
- MIT
- First release
- May 31, 2020
| Version | Released | |
|---|---|---|
0.11.0
minor
|
0.11.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.10.0
minor
|
0.10.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.9.0
unknown
|
0.9.0
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.8.0
unknown
|
0.8.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.7.0
unknown
|
0.7.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.6.0
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.5.0
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.4.0
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.3.0
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.2
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.2.2
unknown
Dependencies (8)
Changelog
Compare changes
|
|
0.2.0
unknown
yanked
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |
0.2.0
unknown
yanked
Dependencies (8)
Changelog
Compare changes
|
|
0.1.0
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.30
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.29
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.28
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.27
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.26
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.25
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.24
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.23
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.22
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.21
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.20
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.19
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.18
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.17
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.16
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.15
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.14
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.13
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.12
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.9
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.8
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.7
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.6
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.5
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.4
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.3
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.2
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.1
unknown
1 CVE
CVE-2026-35365
GHSA-h444-6j9x-p8vh
Jul 06, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
6.6
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
High
Low
When moving directories across filesystems, uutils Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab. Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit Fixed in
0.7.0
References
Updated Jul 06, 2026 · Source: OSV.dev |