Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56392

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

A flaw was found in GNU coreutils, specifically in the unexpand utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when unexpand processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the unexpand utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.

Отчет

A Moderate impact heap-based buffer overflow flaw was found in the unexpand utility of GNU coreutils. This vulnerability arises from an integer overflow when processing unusually large tab stop values, leading to an undersized buffer. A local attacker could exploit this by providing crafted input, causing the utility to crash and potentially leading to a denial of service or arbitrary memory manipulation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10coreutilsAffected
Red Hat Enterprise Linux 6coreutilsOut of support scope
Red Hat Enterprise Linux 7coreutilsOut of support scope
Red Hat Enterprise Linux 9coreutilsAffected
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Enterprise Linux 8coreutilsFixedRHBA-2026:4711529.07.2026
Red Hat Hardened Imagescoreutils-main-9.11-5.hum1FixedRHSA-2026:4072416.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2506694coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values

EPSS

Процентиль: 5%
0.00149
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
9 дней назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

nvd
9 дней назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

msrc
9 дней назад

Heap-based Buffer Overflow in GNU coreutils

debian
9 дней назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow d ...

github
9 дней назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

EPSS

Процентиль: 5%
0.00149
Низкий

4.4 Medium

CVSS3

Уязвимость CVE-2026-56392