The recursive-descent TOCTOU fixed in 0.10.0 (GHSA-32xv-mj27-3qgj) hardened the descent (subdirectory entries are opened NoFollow), but the top-level operand is still opened by path with follow semantics after a separate symlink_metadata check, with no inode re-verification.
src/uu/rm/src/platform/unix.rs:297 reads the operand's mode/device via fs::symlink_metadata(path).
src/uu/rm/src/platform/unix.rs:318 re-resolves the same path with DirFd::open(path, SymlinkBehavior::Follow).
A directory operand swapped for a symlink-to-directory in that window is followed off the intended subtree. Exposure is the same precondition class as the descent finding (attacker controls the operand path or its parent) and matches GNU operand-dereference semantics, so this is a residual/partial-fix gap.
Static finding from a Codex Deep Scan (2026-06-24); no runtime PoC yet.
Remediation: re-verify the opened operand against the symlink_metadata result (compare st_dev/st_ino), or open the operand NoFollow and reconcile the command-line dereference explicitly.
The recursive-descent TOCTOU fixed in 0.10.0 (GHSA-32xv-mj27-3qgj) hardened the descent (subdirectory entries are opened NoFollow), but the top-level operand is still opened by path with follow semantics after a separate
symlink_metadatacheck, with no inode re-verification.src/uu/rm/src/platform/unix.rs:297reads the operand's mode/device viafs::symlink_metadata(path).src/uu/rm/src/platform/unix.rs:318re-resolves the same path withDirFd::open(path, SymlinkBehavior::Follow).A directory operand swapped for a symlink-to-directory in that window is followed off the intended subtree. Exposure is the same precondition class as the descent finding (attacker controls the operand path or its parent) and matches GNU operand-dereference semantics, so this is a residual/partial-fix gap.
Static finding from a Codex Deep Scan (2026-06-24); no runtime PoC yet.
Remediation: re-verify the opened operand against the
symlink_metadataresult (compare st_dev/st_ino), or open the operand NoFollow and reconcile the command-line dereference explicitly.