PatchSiren cyber security CVE debrief
CVE-2026-35381 Uutils CVE debrief
The `cut` command in uutils coreutils has a vulnerability that causes it to ignore the `-s` flag when used with `-z -d ''`. This results in undelimited records being emitted, potentially leading to incorrect data processing in pipelines that rely on `cut -s` for filtering. System administrators and developers using uutils coreutils should assess the impact on their data processing pipelines and verify filtering to ensure correct processing. The issue was identified in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026, with the audited commit being `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`.
- Vendor
- Uutils
- Product
- uu_cut
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-06
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-07-06
- Advisory updated
- 2026-10-06
Who should care
System administrators and developers who use uutils coreutils and rely on `cut -s` to filter undelimited records should assess the impact of this vulnerability on their data processing pipelines.
Why it matters
The `cut` command vulnerability in uutils coreutils may cause incorrect data processing in pipelines that rely on `cut -s` to filter undelimited records. System administrators and developers should assess the impact and verify data filtering to ensure correct processing.
- Data processing pipelines that rely on `cut -s` may process undelimited records incorrectly.
- Verification of data filtering is necessary to ensure correct processing.
Technical summary
The `cut` command in uutils coreutils incorrectly ignores the `-s` flag when used with `-z -d ''`, causing undelimited records to be emitted. This may lead to unexpected data processing in pipelines relying on `cut -s` to filter records. The vulnerability was identified in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026. The issue arises from a special newline-delimiter path for `-z -d ''` that bypasses the `-s` only-delimited flag, resulting in whole undelimited records (plus NUL) being emitted.
Defensive priority
Assess and verify the impact of this vulnerability on data processing pipelines that use `cut -s`.
Recommended defensive actions
- Verify data processing pipelines that use `cut -s` to ensure correct filtering of undelimited records.
- Assess the impact of this vulnerability on your systems and applications.
- Consider updating to version 0.8.0 of uutils coreutils, which includes the fix.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The issue was reported in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026. The audited commit is `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Evidence is limited to this assessment and related CVE details. Defenders should verify data processing pipelines that use `cut -s` and assess the impact of this vulnerability on their systems and applications.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35381 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35381
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35381 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35381
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
cut: -s ignored in -z -d '' newline-delimiter mode
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/crates.io/GHSA-pmfc-4wjj-gmhx.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/uutils/coreutils/security/advisories/GHSA-pmfc-4wjj-gmhx
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/uutils/coreutils/pull/11394
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/uutils/coreutils/commit/483f13e91830c468262aa1e010e753d6ae99c898
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/uutils/coreutils
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/uutils/coreutils/releases/tag/0.8.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.