medium

CVE-2026-35365

crates.io · uu_mv • crates.io · coreutils

Summary

mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)

Severity
medium
CVSS
6.6
EPSS
0.2% (p6)
CWE
CWE-59, CWE-400
Also known as
GHSA-66fx-fqv6-5wwx, GHSA-h444-6j9x-p8vh
Published
2026-07-06
Updated
2026-07-06

Advisory details

When moving directories across filesystems, uutils mv dereferences symlinks inside the tree, copying their targets as real files/dirs instead of preserving the symlinks. GNU preserves symlinks by default. E.g. a etc_link -> /etc inside the source becomes a full copy of /etc at the destination.

Impact: (1) resource exhaustion — a small tree can expand into a huge copy (time/disk DoS); (2) unintended duplication of sensitive paths referenced by symlink; (3) symlink-loop amplification causing deep recursion. Recommendation: in cross-device fallback, detect symlinks via symlink_metadata() and recreate with read_link()/symlink(); add loop detection.

Remediation: Acknowledged by Canonical; fixed in commit 9654e4ab.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.63. Credit: Zellic.

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.