Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56391

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.

Отчет

This Moderate flaw in GNU coreutils uniq allows an out-of-bounds read when processing specially crafted multibyte input with the --check-chars option. An attacker providing malicious input to uniq could trigger a denial of service due to an application crash, and potentially disclose adjacent heap memory. Exploitation requires local user interaction to execute uniq with the vulnerable options and input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10coreutilsAffected
Red Hat Enterprise Linux 6coreutilsOut of support scope
Red Hat Enterprise Linux 7coreutilsOut of support scope
Red Hat Enterprise Linux 8coreutilsFix deferred
Red Hat Enterprise Linux 9coreutilsFix deferred
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Hardened Imagescoreutils-main-9.11-5.1.hum1FixedRHSA-2026:4651527.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2506691coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input

EPSS

Процентиль: 3%
0.00135
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

ubuntu
11 дней назад

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

nvd
11 дней назад

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

debian
11 дней назад

GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read du ...

github
11 дней назад

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

EPSS

Процентиль: 3%
0.00135
Низкий

6.1 Medium

CVSS3