CVE-2026-35341

Description

A flaw was found in uutils coreutils mkfifo. This vulnerability allows a local user to inadvertently change the permissions of an existing file when attempting to create a named pipe (FIFO) at the same location. The mkfifo utility, instead of failing, proceeds to set the existing file's permissions to a default, often less restrictive, mode. This unauthorized modification could expose sensitive data, such as SSH private keys, to other users on the system.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Confidentiality,Integrity

Technical Impact: Read Application Data; Modify Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.