CVE-2026-35361
LOWDescription
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove device nodes or FIFOs. This leaves mislabeled nodes behind with incorrect default contexts, potentially allowing unauthorized access to device nodes that should have been restricted by mandatory access controls.
Is your site exposed to CVE-2026-35361?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| uutils | coreutils |
References
Frequently Asked Questions
What is CVE-2026-35361? +
How severe is CVE-2026-35361? +
What products are affected by CVE-2026-35361? +
How do I check if I'm vulnerable to CVE-2026-35361? +
Related Vulnerabilities
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
SystemUI has an incorrect component protection setting, which allows access to specific information.
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …