« Volver al listado

CVE-2026-35343

Estado: AnalizadaBaja (3.3)—

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been suppressed. This can lead to unexpected data being passed to downstream scripts that rely on strict output filtering.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-35343",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-35343",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-22T18:05:34.291062Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/uutils/coreutils",
          "vendor": "Uutils",
          "product": "coreutils",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.8.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux",
            "Unix",
            "macOS"
          ],
          "packageName": "coreutils",
          "collectionURL": "https://github.com/uutils",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-22T17:16:36.357",
  "references": [
    {
      "url": "https://github.com/uutils/coreutils/pull/11143",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://github.com/uutils/coreutils/releases/tag/0.7.0",
      "tags": [
        "Release Notes"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-670"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been suppressed. This can lead to unexpected data being passed to downstream scripts that rely on strict output filtering."
    }
  ],
  "lastModified": "2026-06-17T10:40:25.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F64F6A4-00A5-4FB8-BB51-21F475C11FF2",
              "versionEndExcluding": "0.7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}