Description
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are destroyed (e.g., /dev/null becomes a regular file). This behavior can lead to runtime denial of service through disk exhaustion or process hangs when reading from unbounded device nodes.
References
https://github.com/uutils/coreutils/issues/9746
https://github.com/uutils/coreutils/pull/11163
https://github.com/uutils/coreutils/issues/9746
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
4.4 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-04-22T17:16:38.393Z
5 months agoLast modified
2026-06-17T10:40:27.330Z
3 months ago