Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14104

Опубликовано: 05 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.1

Описание

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

РелизСтатусПримечание
devel

not-affected

code not compiled
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

not-affected

code not compiled
noble

not-affected

code not compiled
plucky

not-affected

code not compiled
questing

not-affected

code not compiled

Показывать по

EPSS

Процентиль: 8%
0.00183
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
8 месяцев назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
nvd
8 месяцев назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
msrc
7 месяцев назад

Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

CVSS3: 6.1
debian
8 месяцев назад

A flaw was found in util-linux. This vulnerability allows a heap buffe ...

suse-cvrf
6 месяцев назад

Security update for util-linux

EPSS

Процентиль: 8%
0.00183
Низкий

6.1 Medium

CVSS3