Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13654

Опубликовано: 05 дек. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

A flaw was found in duc. This vulnerability allows an out-of-bounds read via a stack buffer overflow in the buffer_get function, where a condition can evaluate to true due to underflow.

Отчет

This vulnerability is rated Important for Red Hat products as it affects the duc package, available in Community Projects (EPEL and Fedora). A stack buffer overflow in the buffer_get function of duc can lead to an out-of-bounds read, potentially resulting in a denial of service. Exploitation does not require user interaction or elevated privileges.

Меры по смягчению последствий

To mitigate this issue, if the duc package is not required, it can be removed from the system. If duc functionality is necessary, restrict its use to trusted administrators and ensure it is executed in a controlled environment to limit potential exposure.

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2419317duc: duc: Stack Buffer Overflow in buffer_get function

EPSS

Процентиль: 56%
0.00859
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
9 месяцев назад

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

CVSS3: 7.5
nvd
9 месяцев назад

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

CVSS3: 7.5
debian
9 месяцев назад

A stack buffer overflow vulnerability exists in the buffer_get functio ...

CVSS3: 7.5
github
9 месяцев назад

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

EPSS

Процентиль: 56%
0.00859
Низкий

7.5 High

CVSS3