---
id: CVE-2026-35341
aliases:
  - GHSA-pmf6-rcx4-v53v
title: 'mkfifo: permissions of an existing file are changed after FIFO creation fails'
summary: 'mkfifo: permissions of an existing file are changed after FIFO creation fails'
severity: high
cvss: 7.1
cwe:
  - CWE-281
  - CWE-732
vendor: uu_mkfifo
product: uu_mkfifo
ecosystem: rust
affected:
  - uu_mkfifo < 0.6.0
patched:
  - uu_mkfifo 0.6.0
published: '2026-07-06'
updated: '2026-07-06'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-pmf6-rcx4-v53v'
references:
  - url: >-
      https://github.com/uutils/coreutils/security/advisories/GHSA-pmf6-rcx4-v53v
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35341'
  - url: 'https://github.com/uutils/coreutils/issues/10020'
  - url: 'https://github.com/uutils/coreutils/pull/10376'
  - url: 'https://github.com/advisories/GHSA-pmf6-rcx4-v53v'
tags:
  - ghsa
  - rust
epss: 0.00165
epssPercentile: 0.06176
ingestedAt: '2026-07-06T22:47:14.058Z'
---

## Overview

When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissions` and changes the permissions of the pre-existing file to the default FIFO mode (`0o666` & umask -> `0644`).

```
$ touch secret; chmod 000 secret
$ coreutils mkfifo secret fifo3 fifo4
mkfifo: cannot create fifo 'secret': File exists
$ ll secret      # uutils:
prw-r--r-- secret   # changed to 644 (GNU leaves it 000)
```

**Impact:** an attacker (or user error) can relax permissions on sensitive owner-only files such as SSH private keys, exposing them to other users. Recommendation: add `continue;` after the error.

**Remediation:** Acknowledged by Canonical; fixed in PR #10376.

---
_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.8. Credit: Zellic._

_Upstream tracking issue: https://github.com/uutils/coreutils/issues/10020 · CVE-2026-35341_

## Affected packages

- `uu_mkfifo < 0.6.0`

## Remediation

Upgrade to a patched release:

- `uu_mkfifo 0.6.0`
