Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw prevents the utility from performing proper short-circuiting for logical OR (|) and AND (&) operations. As a result, arithmetic errors (such as division by zero) occurring within "dead" branches, branches that should be ignored due to short-circuiting, are raised as fatal errors. This divergence from GNU expr behavior can cause guarded expressions within shell scripts to fail with hard errors instead of returning expected boolean results, leading to premature script termination and breaking GNU-compatible shell control flow. | |
| Title | uutils coreutils expr Local Denial of Service via Eager Evaluation of Parenthesized Subexpressions | |
| Weaknesses | CWE-768 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-22T17:00:13.453Z
Reserved: 2026-04-02T12:58:56.089Z
Link: CVE-2026-35378
Updated: 2026-04-22T16:59:45.867Z
Status : Awaiting Analysis
Published: 2026-04-22T17:16:42.730
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-35378
No data.
OpenCVE Enrichment
Updated: 2026-04-22T18:15:15Z