{"id":"CVE-2026-35369","aliases":["GHSA-p6rv-2qpm-fwvg"],"title":"kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)","summary":"kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)","severity":"medium","cvss":5.5,"cwe":["CWE-20","CWE-754"],"vendor":"uu_kill","product":"uu_kill","ecosystem":"rust","affected":["uu_kill < 0.6.0"],"patched":["uu_kill 0.6.0"],"published":"2026-07-06","updated":"2026-07-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p6rv-2qpm-fwvg","references":[{"url":"https://github.com/uutils/coreutils/security/advisories/GHSA-p6rv-2qpm-fwvg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35369"},{"url":"https://github.com/uutils/coreutils/pull/9700"},{"url":"https://github.com/uutils/coreutils/commit/2d3aebce6712841bc08b9b94e9078be50a25fc10"},{"url":"https://github.com/uutils/coreutils/releases/tag/0.6.0"},{"url":"https://github.com/advisories/GHSA-p6rv-2qpm-fwvg"}],"tags":["ghsa","rust"],"epss":0.00128,"epssPercentile":0.02779,"ingestedAt":"2026-07-06T20:46:12.683Z","slug":"CVE-2026-35369","body":"## Overview\n\n`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports \"not enough arguments\".\n\n```\n$ kill -1        # uutils: kill(-1, SIGTERM) -> mass termination / crash\n$ kill -1        # GNU: kill: not enough arguments\n```\n\n**Impact:** a user running `kill -1` mass-terminates processes, potentially crashing the system. Recommendation: parse `-N` as a signal number, and error with \"not enough arguments\" when no PID is given.\n\n**Remediation:** Acknowledged by Canonical; fixed in commit cae94028.\n\n---\n_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.70. Credit: Zellic._\n\n## Affected packages\n\n- `uu_kill < 0.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `uu_kill 0.6.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}