Skip to content

rm -r: top-level operand can be raced before fd-based traversal (TOCTOU)

High
sylvestre published GHSA-9gw8-m5cj-3cr6 Sep 5, 2026

Package

cargo uu_rm (Rust)

Affected versions

<= 0.10.0

Patched versions

0.11.0

Description

The recursive-descent TOCTOU fixed in 0.10.0 (GHSA-32xv-mj27-3qgj) hardened the descent (subdirectory entries are opened NoFollow), but the top-level operand is still opened by path with follow semantics after a separate symlink_metadata check, with no inode re-verification.

  • src/uu/rm/src/platform/unix.rs:297 reads the operand's mode/device via fs::symlink_metadata(path).
  • src/uu/rm/src/platform/unix.rs:318 re-resolves the same path with DirFd::open(path, SymlinkBehavior::Follow).

A directory operand swapped for a symlink-to-directory in that window is followed off the intended subtree. Exposure is the same precondition class as the descent finding (attacker controls the operand path or its parent) and matches GNU operand-dereference semantics, so this is a residual/partial-fix gap.

Static finding from a Codex Deep Scan (2026-06-24); no runtime PoC yet.

Remediation: re-verify the opened operand against the symlink_metadata result (compare st_dev/st_ino), or open the operand NoFollow and reconcile the command-line dereference explicitly.

Severity

High

CVE ID

No known CVE

Weaknesses

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. Learn more on MITRE.

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. Learn more on MITRE.

Credits