Feed/CVE-2026-35369
CVE-2026-35369MEDIUMCVSS 5.5

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

Published Jul 6, 2026·Updated Jul 6, 2026

NVD Description

`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports "not enough arguments". ``` $ kill -1 # uutils: kill(-1, SIGTERM) -> mass termination / crash $ kill -1 # GNU: kill: not enough arguments ``` **Impact:** a user running `kill -1` mass-terminates processes, potentially crashing the system. Recommendation: parse `-N` as a signal number, and error with "not enough arguments" when no PID is given. **Remediation:** Acknowledged by Canonical; fixed in commit cae94028. --- _Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.70. Credit: Zellic._

Affected Packages (1)

uu_killCARGO
Fixed in 0.6.0

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free