CVE Vulnerabilities

CVE-2026-35348

Uncaught Exception

Published: Apr 22, 2026 | Modified: Apr 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The sort utility in uutils coreutils is vulnerable to a process panic when using the –files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort, which treats filenames as raw bytes. A local attacker can exploit this to crash the utility and disrupt automated pipelines.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
CoreutilsUutils- (including)- (including)
Rust-coreutilsUbuntudevel*
Rust-coreutilsUbuntuesm-apps/noble*
Rust-coreutilsUbuntunoble*
Rust-coreutilsUbuntuquesting*
Rust-coreutilsUbunturesolute*
Rust-coreutilsUbuntuupstream*

References