Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-33124

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-33124: coreutils security update (MODERATE)

[9.5-8.0.1]

  • clean up empty file if cp is failed [Orabug 15973168]

[9.5-8]

  • CVE-2025-5278 - Fix Heap Buffer Under-Read in sort via Key Specification (RHEL-180649)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

coreutils

9.5-8.0.1.el10_2

coreutils-common

9.5-8.0.1.el10_2

coreutils-single

9.5-8.0.1.el10_2

Oracle Linux x86_64

coreutils

9.5-8.0.1.el10_2

coreutils-common

9.5-8.0.1.el10_2

coreutils-single

9.5-8.0.1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
redhat
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
nvd
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
debian
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() funct ...

suse-cvrf
около 1 года назад

Security update for coreutils