Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14104

Опубликовано: 05 дек. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 6.1

Описание

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

РелизСтатусПримечание
devel

not-affected

code not compiled
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

needs-triage

jammy

not-affected

code not compiled
noble

not-affected

code not compiled
plucky

not-affected

code not compiled
questing

not-affected

code not compiled
upstream

released

2.41.3-1

Показывать по

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVSS3: 6.1
msrc
около 1 месяца назад

Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

CVSS3: 6.1
debian
2 месяца назад

A flaw was found in util-linux. This vulnerability allows a heap buffe ...

suse-cvrf
5 дней назад

Security update for util-linux

suse-cvrf
17 дней назад

Security update for util-linux

6.1 Medium

CVSS3