{"id":"CVE-2026-35361","aliases":["GHSA-r9hw-mj3w-phcq"],"title":"mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)","summary":"mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)","severity":"low","cvss":3.4,"cwe":["CWE-281","CWE-459","CWE-732"],"vendor":"uu_mknod","product":"uu_mknod","ecosystem":"rust","affected":["uu_mknod < 0.6.0"],"patched":["uu_mknod 0.6.0"],"published":"2026-07-06","updated":"2026-07-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-r9hw-mj3w-phcq","references":[{"url":"https://github.com/uutils/coreutils/security/advisories/GHSA-r9hw-mj3w-phcq"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35361"},{"url":"https://github.com/uutils/coreutils/pull/10582"},{"url":"https://github.com/uutils/coreutils/commit/42b2ad83cdcf6e959ecb378c5040c60d9c64becf"},{"url":"https://github.com/uutils/coreutils/releases/tag/0.6.0"},{"url":"https://github.com/advisories/GHSA-r9hw-mj3w-phcq"}],"tags":["ghsa","rust"],"epss":0.00142,"epssPercentile":0.03906,"ingestedAt":"2026-07-06T22:47:14.055Z","slug":"CVE-2026-35361","body":"## Overview\n\nuutils calls `mknod` *before* setting the SELinux context (GNU uses `setfscreatecon` first, labeling atomically). If `set_selinux_security_context` fails, cleanup uses `std::fs::remove_dir`, which cannot remove device nodes or FIFOs, leaving the mislabeled node behind.\n\n**Impact:** on SELinux-enforcing systems the node is created with the wrong context; the command reports failure but leaves a mislabeled device node that may bypass mandatory access control, and orphaned nodes can persist across reboots. Recommendation: use `setfscreatecon` before `mknod`, abort on failure, and use `remove_file` for cleanup.\n\n**Remediation:** Acknowledged by Canonical.\n\n---\n_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.58. Credit: Zellic._\n\n## Affected packages\n\n- `uu_mknod < 0.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `uu_mknod 0.6.0`","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":18.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}