[slackware-security] coreutils (SSA:2024-088-03)

Posted on 29 March 2024
Slackware Security

New coreutils packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
patches/packages/coreutils-9.5-i586-1_slack15.0.txz: Upgraded.
chmod -R now avoids a race where an attacker may replace a traversed file
with a symlink, causing chmod to operate on an unintended file.
[This bug was present in "the beginning".]
split --line-bytes with a mixture of very long and short lines no longer
overwrites the heap.
For more information, see:
(* Security fix *)

Where to find the new packages:

Updated package for Slackware 15.0:

Updated package for Slackware x86_64 15.0:

Updated package for Slackware -current:

Updated package for Slackware x86_64 -current:

Installation instructions:

Upgrade the package as root:
# upgradepkg coreutils-9.5-i586-1_slack15.0.txz


Slackware Linux Security Team