CVE-2026-35379

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:] class and excludes it from the [:print:] class, effectively reversing the standard behavior established by POSIX and GNU coreutils. This vulnerability leads to unintended data modification or loss when the utility is used in automated scripts or data-cleaning pipelines that rely on standard character class semantics. For example, a command executed to delete all graphical characters while intending to preserve whitespace will incorrectly delete all ASCII spaces, potentially resulting in data corruption or logic failures in downstream processing.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*

History

29 Apr 2026, 15:59

Type Values Removed Values Added
References () https://github.com/uutils/coreutils/pull/11405 - () https://github.com/uutils/coreutils/pull/11405 - Exploit, Issue Tracking, Patch
References () https://github.com/uutils/coreutils/releases/tag/0.8.0 - () https://github.com/uutils/coreutils/releases/tag/0.8.0 - Release Notes
First Time Uutils
Uutils coreutils
CPE cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:*

22 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 17:16

Updated : 2026-04-29 15:59


NVD link : CVE-2026-35379

Mitre link : CVE-2026-35379

CVE.ORG link : CVE-2026-35379


JSON object : View

Products Affected

uutils

  • coreutils
CWE
CWE-684

Incorrect Provision of Specified Functionality