Intel

AIKIDO-2026-590380

uu_mv is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)CVE-2026-35354 Published Aug 11, 2026

47

Medium Risk

This Affects:

RUSTuu_mv
0.0.1 - 0.10.0
Fixed in 0.11.0
Are you affected? Scan for Free

TL;DR

The mv utility preserves extended attributes during cross-device moves using repeated path-based syscalls that re-resolve the source and destination on each call. Because the reads and writes are not anchored to a stable file descriptor, a local user who can write to the directory can swap files between calls. This lets the destination end up with an inconsistent mix of security-relevant xattrs such as SELinux labels or file capabilities. 0.9.0 pinned the regular-file EXDEV fallback to file descriptors, but directory fallback still used path-based xattr list/set. The complete fix performs xattr preservation against pinned file descriptors for both files and directories so the operation is inode-stable.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you move files or directories carrying security extended attributes across filesystem boundaries in a directory that untrusted local users can write to.

Background info

uu_mv is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 0.10.0.

How to fix this

Upgrade the uu_mv library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform