CVE-2026-35379
Błąd logiczny w narzędziu tr w uutils coreutils prowadzi do utraty danych przez błędne klasy znaków.
A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:] class and excludes it from the [:print:] class, effectively reversing the standard behavior established by POSIX and GNU coreutils. This vulnerability leads to unintended data modification or loss when the utility is used in automated scripts or data-cleaning pipelines that rely on standard character class semantics. For example, a command executed to delete all graphical characters while intending to preserve whitespace will incorrectly delete all ASCII spaces, potentially resulting in data corruption or logic failures in downstream processing.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-04-22 17:16:42 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-29 15:59:08 UTC |
- https://github.com/uutils/coreutils/pull/11405 (security@ubuntu.com) [Exploit, Issue Tracking, Patch]
- https://github.com/uutils/coreutils/releases/tag/0.8.0 (security@ubuntu.com) [Release Notes]