{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/vex/2026/cve-2026-35345-els_os-almalinux9_2esu.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-16T19:58:20Z",
      "generator": {
        "date": "2026-07-16T19:58:20Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-35345-ELS_OS-ALMALINUX9.2ESU",
      "initial_release_date": "2026-04-22T17:16:00Z",
      "revision_history": [
        {
          "date": "2026-04-22T17:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-16T19:58:20Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-35345"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_id": "coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/coreutils@8.32-34.el9.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_id": "coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/coreutils-single@8.32-34.el9.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_id": "coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/coreutils-common@8.32-34.el9.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "coreutils-0:8.32-34.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:coreutils-0:8.32-34.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-35345",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently outputting the contents of the link's target. In environments where a privileged user (e.g., root) monitors a log directory, a local attacker with write access to that directory can replace a log file with a symlink to a sensitive system file (such as /etc/shadow), causing tail to disclose the contents of the sensitive file.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "AlmaLinux-9.2:coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-35345"
        },
        {
          "category": "external",
          "summary": "https://github.com/uutils/coreutils/issues/10328",
          "url": "https://github.com/uutils/coreutils/issues/10328"
        }
      ],
      "release_date": "2026-04-22T17:16:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        },
        {
          "category": "impact",
          "date": "2026-06-12T12:56:42.630235Z",
          "details": "unknown",
          "product_ids": [
            "AlmaLinux-9.2:coreutils-0:8.32-34.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:coreutils-common-0:8.32-34.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:coreutils-single-0:8.32-34.el9.tuxcare.els1.x86_64"
          ]
        }
      ]
    }
  ]
}