Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrx4-rccm-xj6c

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

EPSS

Процентиль: 3%
0.00015
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
nvd
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
msrc
около 1 месяца назад

Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

CVSS3: 6.1
debian
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffe ...

suse-cvrf
6 дней назад

Security update for util-linux

EPSS

Процентиль: 3%
0.00015
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125