{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://index.kapsl.sh/vex/coreutils-core-amd64",
  "author": "kapsl index <https://index.kapsl.sh>",
  "timestamp": "2026-08-26T13:47:18Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2026-54371"
      },
      "products": [
        {
          "@id": "pkg:deb/ubuntu/attr@1%3A2.5.2-4?distro=ubuntu-26.04"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The advisory is explicit that the symlink-traversal flaw is in the getfattr\nand setfattr UTILITIES, not in libattr. The finding arises because the SBOM\nnames the SOURCE package `attr`, which is what the advisory is filed against\nand which builds both the library and the utilities. That is correct SBOM\nbehaviour and the right purl to carry; it just means the match is at source\ngranularity while the vulnerability is at binary granularity.\n\nThe operative claim is the predicate below: this image ships neither utility,\nso the vulnerable code is not in the artifact. It is NOT that libattr is\nunused -- an image carries libattr.so.1 because something in it preserves\nextended attributes, which is the library path and reaches neither utility.\nWhich programs those are differs per image and does not change the\nassessment.\n\nThis text used to name cp, install and mv as the linkers. That was true of\ncoreutils, where it was written, and wrong for the other images carrying the\nstatement, so it now states the rule rather than one image's inventory."
    }
  ]
}
