Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5278

Опубликовано: 27 мая 2025
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Отчет

The severity of this issue is considered Moderate rather than Critical because successful exploitation requires the use of the traditional key specification syntax with an exceptionally large character position value, which is uncommon in typical usage. Although the vulnerability can lead to a heap buffer overflow resulting in a read one byte before the allocated buffer, it does not enable code execution, privilege escalation, or direct compromise of data confidentiality or integrity. The impact is therefore primarily limited to potential service disruption due to application crashes. Furthermore, default RHEL configurations such as SELinux enforcement, ASLR, and memory protections reduce the likelihood of exploitation and limit the scope of any resulting impact. These safeguards, along with typical system usage patterns that do not commonly invoke the vulnerable code path, restrict exploitability in default and hardened environments. Consequently, the vulnerability’s overall security impact is mitigated compared to flaws that allow immediate code execution or broader compromise across system components.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6coreutilsOut of support scope
Red Hat Enterprise Linux 7coreutilsOut of support scope
Red Hat Enterprise Linux 8coreutilsFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10coreutilsFixedRHSA-2026:3312429.06.2026
Red Hat Enterprise Linux 9coreutilsFixedRHSA-2026:2891124.06.2026
Cost Management Metrics Operator 4costmanagement/costmanagement-metrics-rhel9-operatorFixedRHSA-2026:3998115.07.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:3331329.06.2026
Red Hat Insights proxy 1.5insights-proxy/insights-proxy-container-rhel9FixedRHSA-2026:3410201.07.2026
Red Hat OpenShift distributed tracing 3.10.0rhosdt/tempo-gateway-opa-rhel9FixedRHSA-2026:3361230.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2368764coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification

EPSS

Процентиль: 14%
0.00233
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
nvd
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
debian
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() funct ...

suse-cvrf
около 1 года назад

Security update for coreutils

suse-cvrf
около 1 года назад

Security update for coreutils

EPSS

Процентиль: 14%
0.00233
Низкий

4.4 Medium

CVSS3