Intel

AIKIDO-2026-110809

uu_mv is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)GHSA-pp2g-c3j7-j725 Published 5 days ago

66

Medium Risk

This Affects:

RUSTuu_mv
0.0.1 - 0.9.0
Fixed in 0.10.0
Are you affected? Scan for Free

TL;DR

mv's cross filesystem fallback for directories removes the destination with fs::remove_dir_all and then recreates it with path based fs::create_dir_all/fs::copy calls. A local user who can write to the destination's parent directory can plant a symlink in the window between the removal and the recreate, causing the path based copy to follow it and write outside the intended tree while the source is deleted. The single file and symlink target fallbacks were hardened separately, but the directory fallback kept removing the destination and recreating it by path. The fix applies the same fail closed, non-following approach used for the other fallbacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run a privileged cross filesystem mv of a directory into a destination whose parent directory an untrusted local user can write to.

Background info

uu_mv is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 0.9.0.

How to fix this

Upgrade the uu_mv library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform