CVE-2026-35346 LOW

CVE-2026-35346: uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization

Vendor Uutils
Product coreutils
Weakness CWE-176
Published April 22, 2026
Last update April 22, 2026

CVSS base score

3.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 byte sequences with the Unicode replacement character (U+FFFD). This behavior differs from GNU comm, which processes raw bytes and preserves the original input. This results in corrupted output when the utility is used to compare binary files or files using non-UTF-8 legacy encodings.

Key dates

02Disclosure timeline

April 22, 2026 CVE published
April 22, 2026 Record updated