cvedb.io
CVE-2026-35367
LOW · CVSS 3.3
EPSS exploitation probability: 0%
Published 2026-04-22T17:16:40.423 · Last modified 2026-06-17T10:40:28.297

Summary

The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, typically resulting in a world-readable file (0644). In multi-user environments, this allows any user on the system to read the captured stdout/stderr output of a command, potentially exposing sensitive information. This behavior diverges from GNU coreutils, which creates nohup.out with owner-only (0600) permissions.

Affected products

uutils — coreutils

Does this affect you?

Add your gear to cvedb and we'll alert you only when uutils ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.