CVE-2026-35346: CWE-176: Improper Handling of Unicode Encoding in Uutils coreutils
The comm utility in uutils coreutils improperly handles Unicode encoding by performing lossy UTF-8 conversion on all output lines. This causes silent data corruption when comparing binary files or files with non-UTF-8 encodings, as invalid UTF-8 sequences are replaced with the Unicode replacement character. This behavior differs from GNU comm, which preserves raw byte data. The vulnerability has a low severity score and no known exploits in the wild.
AI Analysis
Technical Summary
CVE-2026-35346 describes a vulnerability in the comm utility of uutils coreutils where the use of String::from_utf8_lossy() leads to lossy UTF-8 conversion of output lines. Invalid UTF-8 byte sequences are replaced with U+FFFD, resulting in corrupted output when processing binary or legacy-encoded files. Unlike GNU comm, which processes raw bytes without modification, uutils coreutils' comm utility alters the data, causing integrity issues in output. The vulnerability is classified under CWE-176 (Improper Handling of Unicode Encoding).
Potential Impact
The vulnerability causes integrity loss in the output of the comm utility when used on binary files or files with non-UTF-8 encodings. This can lead to silent data corruption, potentially misleading users relying on accurate file comparisons. There is no impact on confidentiality or availability. The CVSS score of 3.3 reflects a low severity with limited impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using uutils coreutils comm utility for comparing binary or non-UTF-8 encoded files or use GNU comm as an alternative.
CVE-2026-35346: CWE-176: Improper Handling of Unicode Encoding in Uutils coreutils
Description
The comm utility in uutils coreutils improperly handles Unicode encoding by performing lossy UTF-8 conversion on all output lines. This causes silent data corruption when comparing binary files or files with non-UTF-8 encodings, as invalid UTF-8 sequences are replaced with the Unicode replacement character. This behavior differs from GNU comm, which preserves raw byte data. The vulnerability has a low severity score and no known exploits in the wild.
CVSS v3.1
Score 3.3low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-35346 describes a vulnerability in the comm utility of uutils coreutils where the use of String::from_utf8_lossy() leads to lossy UTF-8 conversion of output lines. Invalid UTF-8 byte sequences are replaced with U+FFFD, resulting in corrupted output when processing binary or legacy-encoded files. Unlike GNU comm, which processes raw bytes without modification, uutils coreutils' comm utility alters the data, causing integrity issues in output. The vulnerability is classified under CWE-176 (Improper Handling of Unicode Encoding).
Potential Impact
The vulnerability causes integrity loss in the output of the comm utility when used on binary files or files with non-UTF-8 encodings. This can lead to silent data corruption, potentially misleading users relying on accurate file comparisons. There is no impact on confidentiality or availability. The CVSS score of 3.3 reflects a low severity with limited impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using uutils coreutils comm utility for comparing binary or non-UTF-8 encoded files or use GNU comm as an alternative.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- canonical
- Date Reserved
- 2026-04-02T12:58:56.087Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69e8f7ce19fe3cd2cdd00c1a
Added to database: 04/22/2026, 16:31:10 UTC
Last enriched: 07/06/2026, 23:19:17 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.