Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:33124

Опубликовано: 05 июл. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: coreutils security update

The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages.

Security Fix(es):

  • coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification (CVE-2025-5278)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
redhat
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
nvd
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
debian
около 1 года назад

A flaw was found in GNU Coreutils. The sort utility's begfield() funct ...

suse-cvrf
около 1 года назад

Security update for coreutils