Duplicate Advisory: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-w6xc-g9qj-vp32. This link is maintained to preserve external references. ### Original Description The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.
AI Analysis
Technical Summary
The safe_traversal module in uutils coreutils aims to prevent TOCTOU symlink race conditions by using file-descriptor-relative syscalls. However, this protection is limited to Linux platforms. On other Unix-like systems including macOS and FreeBSD, the module does not apply these protections, leaving directory traversal operations exposed to symlink race vulnerabilities. This affects all versions of uutils coreutils prior to 0.6.0.
Potential Impact
On affected non-Linux Unix-like systems, an attacker could exploit the TOCTOU race condition during directory traversal to manipulate symlinks between the time a check is performed and the time a file is used. This could lead to unintended file access or modification. The CVSS vector indicates low confidentiality and integrity impact with no availability impact, requiring local access with high attack complexity and low privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should upgrade to uutils coreutils version 0.6.0 or later once a fix is available. Until then, avoid running vulnerable versions on non-Linux Unix-like systems if possible.
Duplicate Advisory: uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Description
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-w6xc-g9qj-vp32. This link is maintained to preserve external references. ### Original Description The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.
CVSS v3.1
Score 3.6low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The safe_traversal module in uutils coreutils aims to prevent TOCTOU symlink race conditions by using file-descriptor-relative syscalls. However, this protection is limited to Linux platforms. On other Unix-like systems including macOS and FreeBSD, the module does not apply these protections, leaving directory traversal operations exposed to symlink race vulnerabilities. This affects all versions of uutils coreutils prior to 0.6.0.
Potential Impact
On affected non-Linux Unix-like systems, an attacker could exploit the TOCTOU race condition during directory traversal to manipulate symlinks between the time a check is performed and the time a file is used. This could lead to unintended file access or modification. The CVSS vector indicates low confidentiality and integrity impact with no availability impact, requiring local access with high attack complexity and low privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should upgrade to uutils coreutils version 0.6.0 or later once a fix is available. Until then, avoid running vulnerable versions on non-Linux Unix-like systems if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ggc5-46rg-mr4v
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["crates.io"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a4c340827e9c797195f6864
Added to database: 07/06/2026, 23:02:32 UTC
Last enriched: 07/06/2026, 23:15:18 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.