Duplicate Advisory: uutils coreutils has an Incorrect Provision of Specified Functionality Issue in its cut Utility
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-pmfc-4wjj-gmhx. This link is maintained to preserve external references. ### Original Description A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The implementation incorrectly routes this specific combination through a specialized newline-delimiter code path that fails to check the record suppression status. Consequently, uutils cut emits the entire record plus a NUL byte instead of suppressing it. This divergence from GNU coreutils behavior creates a data integrity risk for automated pipelines that rely on cut -s to filter out undelimited data.
AI Analysis
Technical Summary
The vulnerability is a logic error in the uutils coreutils cut utility where the combination of -s, -z, and -d '' options incorrectly bypasses the suppression of undelimited records. The implementation routes this combination through a newline-delimiter code path that does not check record suppression status, causing the entire record plus a NUL byte to be emitted instead of being suppressed. This behavior deviates from GNU coreutils and may cause data integrity risks in automated processing pipelines that depend on cut -s filtering. The advisory is a duplicate and has been withdrawn, with no patch links provided. The affected versions are all versions prior to 0.8.0.
Potential Impact
The impact is limited to data integrity issues in automated pipelines that rely on the cut utility's -s flag to suppress undelimited records. The vulnerability does not affect confidentiality or availability, and no known exploits are reported. The severity is low due to the limited scope and impact.
Mitigation Recommendations
No official patch or fix is indicated in this advisory. Users should upgrade to uutils coreutils version 0.8.0 or later where this issue is presumably resolved. Until then, avoid using the combination of -s, -z, and -d '' options together in the cut utility to prevent incorrect output. Monitor the vendor advisory GHSA-pmfc-4wjj-gmhx for updates and official remediation guidance.
Duplicate Advisory: uutils coreutils has an Incorrect Provision of Specified Functionality Issue in its cut Utility
Description
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-pmfc-4wjj-gmhx. This link is maintained to preserve external references. ### Original Description A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The implementation incorrectly routes this specific combination through a specialized newline-delimiter code path that fails to check the record suppression status. Consequently, uutils cut emits the entire record plus a NUL byte instead of suppressing it. This divergence from GNU coreutils behavior creates a data integrity risk for automated pipelines that rely on cut -s to filter out undelimited data.
CVSS v3.1
Score 3.3low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability is a logic error in the uutils coreutils cut utility where the combination of -s, -z, and -d '' options incorrectly bypasses the suppression of undelimited records. The implementation routes this combination through a newline-delimiter code path that does not check record suppression status, causing the entire record plus a NUL byte to be emitted instead of being suppressed. This behavior deviates from GNU coreutils and may cause data integrity risks in automated processing pipelines that depend on cut -s filtering. The advisory is a duplicate and has been withdrawn, with no patch links provided. The affected versions are all versions prior to 0.8.0.
Potential Impact
The impact is limited to data integrity issues in automated pipelines that rely on the cut utility's -s flag to suppress undelimited records. The vulnerability does not affect confidentiality or availability, and no known exploits are reported. The severity is low due to the limited scope and impact.
Mitigation Recommendations
No official patch or fix is indicated in this advisory. Users should upgrade to uutils coreutils version 0.8.0 or later where this issue is presumably resolved. Until then, avoid using the combination of -s, -z, and -d '' options together in the cut utility to prevent incorrect output. Monitor the vendor advisory GHSA-pmfc-4wjj-gmhx for updates and official remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-532v-xp3f-837c
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["crates.io"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a4c33f027e9c797195ec84b
Added to database: 07/06/2026, 23:02:08 UTC
Last enriched: 07/06/2026, 23:05:26 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 37
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.