CVE-2026-35368Uutils · Coreutils
Vulnerability data via NVD (ingested)
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries (e.g., libnss_*.so.2) from the new root directory. If the NEWROOT is writable by an attacker, they can inject a malicious NSS module to execute arbitrary code as root, facilitating a full container escape or privilege escalation.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-35368product:"Uutils Coreutils"http.html:"Coreutils"More intel sources (5)
vuln:CVE-2026-35368vulnerabilities.cve_id: CVE-2026-35368CVE-2026-35368CVE-2026-35368"CVE-2026-35368" exploit -site:nvd.nist.gov