Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14104

Опубликовано: 05 дек. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
util-linuxfixed2.41.3-1package
util-linuxno-dsatrixiepackage
util-linuxno-dsabookwormpackage
util-linuxpostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2419369

  • https://github.com/util-linux/util-linux/issues/3585

  • https://github.com/util-linux/util-linux/pull/3586

  • Fixed by: https://github.com/util-linux/util-linux/commit/aaa9e718c88d6916b003da7ebcfe38a3c88df8e6

  • Fixed by: https://github.com/util-linux/util-linux/commit/9a36d77012c4c771f8d51eba46b6e62c29bf572a

EPSS

Процентиль: 3%
0.00016
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
nvd
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
msrc
около 1 месяца назад

Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

suse-cvrf
4 дня назад

Security update for util-linux

suse-cvrf
16 дней назад

Security update for util-linux

EPSS

Процентиль: 3%
0.00016
Низкий