PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35381 Uutils CVE debrief

The `cut` command in uutils coreutils has a vulnerability that causes it to ignore the `-s` flag when used with `-z -d ''`. This results in undelimited records being emitted, potentially leading to incorrect data processing in pipelines that rely on `cut -s` for filtering. System administrators and developers using uutils coreutils should assess the impact on their data processing pipelines and verify filtering to ensure correct processing. The issue was identified in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026, with the audited commit being `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`.

Vendor
Uutils
Product
uu_cut
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-06
Original CVE updated
2026-10-06
Advisory published
2026-07-06
Advisory updated
2026-10-06

Who should care

System administrators and developers who use uutils coreutils and rely on `cut -s` to filter undelimited records should assess the impact of this vulnerability on their data processing pipelines.

Why it matters

The `cut` command vulnerability in uutils coreutils may cause incorrect data processing in pipelines that rely on `cut -s` to filter undelimited records. System administrators and developers should assess the impact and verify data filtering to ensure correct processing.

  • Data processing pipelines that rely on `cut -s` may process undelimited records incorrectly.
  • Verification of data filtering is necessary to ensure correct processing.

Technical summary

The `cut` command in uutils coreutils incorrectly ignores the `-s` flag when used with `-z -d ''`, causing undelimited records to be emitted. This may lead to unexpected data processing in pipelines relying on `cut -s` to filter records. The vulnerability was identified in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026. The issue arises from a special newline-delimiter path for `-z -d ''` that bypasses the `-s` only-delimited flag, resulting in whole undelimited records (plus NUL) being emitted.

Defensive priority

Assess and verify the impact of this vulnerability on data processing pipelines that use `cut -s`.

Recommended defensive actions

  • Verify data processing pipelines that use `cut -s` to ensure correct filtering of undelimited records.
  • Assess the impact of this vulnerability on your systems and applications.
  • Consider updating to version 0.8.0 of uutils coreutils, which includes the fix.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The issue was reported in the Zellic uutils coreutils Program Security Assessment for Canonical in January 2026. The audited commit is `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Evidence is limited to this assessment and related CVE details. Defenders should verify data processing pipelines that use `cut -s` and assess the impact of this vulnerability on their systems and applications.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • cut: -s ignored in -z -d '' newline-delimiter mode

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/crates.io/GHSA-pmfc-4wjj-gmhx.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/uutils/coreutils/security/advisories/GHSA-pmfc-4wjj-gmhx

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/uutils/coreutils/pull/11394

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/uutils/coreutils/commit/483f13e91830c468262aa1e010e753d6ae99c898

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/uutils/coreutils

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/uutils/coreutils/releases/tag/0.8.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.