โ† All reports

The 'id' utility in uutils coreutils incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user, leading to incorrect behavior in its 'pretty print' output.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the uutils coreutils project, specifically issues with the 'id' utility's behavior related to UID and GID handling, which could lead to incorrect output and potential security risks.

Claims

The 'id' utility in uutils coreutils incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user, leading to incorrect behavior in its 'pretty print' output.
Parent: Software VulnerabilitiesEntity: uutils coreutilsImpact: negativeDate: Apr 22, 2026Target: The accuracy and reliability of the 'id' utility in uutils coreutils.
The 'id' utility in uutils coreutils miscalculates the groups= section of its output by using the real GID instead of the effective GID, leading to potentially divergent output compared to GNU coreutils.
Parent: Software VulnerabilitiesEntity: uutils coreutilsImpact: negativeDate: Apr 22, 2026Target: The consistency and correctness of the 'id' utility's output in uutils coreutils.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-25018 ๐Ÿ“Š Score: 4.4/10 (CVSS v3.1) ๐Ÿข Vendor: Uutils ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and au... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25018 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25019 ๐Ÿ“Š Score: 3.3/10 (CVSS v3.1) ๐Ÿข Vendor: Uutils ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25019 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability