CVE-2026-35369: Uutils Coreutils

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to PID -1. Sending a signal to PID -1 causes the kernel to terminate all processes visible to the caller, potentially leading to a system crash or massive process termination. This differs from GNU coreutils, which correctly recognizes -1 as a signal number in this context and would instead report a missing PID argument.

Affected products

  • Uutils Coreutils: before 0.6.0 (fixed in 0.6.0)

Published 2026-04-22. Last modified 2026-06-17.