Skip to content

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

Critical
sylvestre published GHSA-p6rv-2qpm-fwvg May 30, 2026

Package

cargo uu_kill (Rust)

Affected versions

< 0.6.0

Patched versions

0.6.0

Description

kill -1 is incorrectly parsed as a positional pid = -1; combined with the default SIGTERM this calls kill(-1, SIGTERM), signaling nearly every process the caller can see. GNU kill recognizes -1/-9 as signals and reports "not enough arguments".

$ kill -1        # uutils: kill(-1, SIGTERM) -> mass termination / crash
$ kill -1        # GNU: kill: not enough arguments

Impact: a user running kill -1 mass-terminates processes, potentially crashing the system. Recommendation: parse -N as a signal number, and error with "not enough arguments" when no PID is given.

Remediation: Acknowledged by Canonical; fixed in commit cae9402.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.70. Credit: Zellic.

Severity

Critical

CVE ID

CVE-2026-35369

Weaknesses

Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. Learn more on MITRE.