securityonline.info 8/21/2026, 3:20:29 PM · external

Local exploit found in uutils stdbuf tool via LD_PRELOAD handling

Local exploit found in uutils stdbuf tool via LD_PRELOAD handling
CyberSIXT Evidence Panel
Primary Source seclists.org

A critical vulnerability has been identified in the uutils coreutils stdbuf tool, allowing local users on shared systems to execute arbitrary code due to its handling of the LD_PRELOAD environment variable. The stdbuf tool creates a world-writable library, potentially enabling attacks by malicious users. This flaw affects various Linux and BSD distributions, such as Fedora and FreeBSD.

While no CVE has been assigned yet, the recommended mitigation is to compile the software with a specific feature enabled to use a properly installed system library. Maintaining a restrictive umask can also help mitigate the risks until a patch is applied.

View Primary Source Via securityonline.info

Article by CyberSIXT