CVE-2026-35369: kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
kill -1 is incorrectly parsed as a positional pid = -1; combined with the default SIGTERM this calls kill(-1, SIGTERM), signaling nearly every process the caller can see. GNU kill recognizes -1/-9 as signals and reports “not enough arguments”.
$ kill -1 # uutils: kill(-1, SIGTERM) -> mass termination / crash
$ kill -1 # GNU: kill: not enough arguments
Impact: a user running kill -1 mass-terminates processes, potentially crashing the system. Recommendation: parse -N as a signal number, and error with “not enough arguments” when no PID is given.
Remediation: Acknowledged by Canonical; fixed in commit cae94028.
Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.70. Credit: Zellic.
References
- github.com/advisories/GHSA-p6rv-2qpm-fwvg
- github.com/uutils/coreutils/commit/2d3aebce6712841bc08b9b94e9078be50a25fc10
- github.com/uutils/coreutils/pull/9700
- github.com/uutils/coreutils/releases/tag/0.6.0
- github.com/uutils/coreutils/security/advisories/GHSA-p6rv-2qpm-fwvg
- nvd.nist.gov/vuln/detail/CVE-2026-35369
Code Behaviors & Features
Detect and mitigate CVE-2026-35369 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →