The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path is a FIFO or a pipe, this pre-read operation drains the stream, leading to silent data loss before the actual comparison logic is executed. Additionally, the utility may hang indefinitely if it attempts to pre-read from infinite streams like /dev/zero.
References
| Link | Resource |
|---|---|
| https://github.com/uutils/coreutils/pull/9545 | Issue Tracking Patch |
| https://github.com/uutils/coreutils/releases/tag/0.6.0 | Release Notes |
| https://github.com/uutils/coreutils/pull/9545 | Issue Tracking Patch |
Configurations
History
27 Apr 2026, 12:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Uutils
Uutils coreutils |
|
| CPE | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | |
| References | () https://github.com/uutils/coreutils/pull/9545 - Issue Tracking, Patch | |
| References | () https://github.com/uutils/coreutils/releases/tag/0.6.0 - Release Notes |
22 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/uutils/coreutils/pull/9545 - |
22 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 17:16
Updated : 2026-04-27 12:28
NVD link : CVE-2026-35347
Mitre link : CVE-2026-35347
CVE.ORG link : CVE-2026-35347
JSON object : View
Products Affected
uutils
- coreutils
CWE
CWE-20
Improper Input Validation
