Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-56392

Опубликовано: 24 июл. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 6.1

Описание

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

РелизСтатусПримечание
devel

not-affected

see notes
esm-infra-legacy/trusty

not-affected

see notes
esm-infra-legacy/xenial

not-affected

see notes
esm-infra/bionic

not-affected

see notes
esm-infra/focal

not-affected

see notes
jammy

not-affected

see notes
noble

not-affected

see notes
resolute

not-affected

see notes
upstream

needs-triage

Показывать по

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
около 2 месяцев назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

CVSS3: 6.1
nvd
около 2 месяцев назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

msrc
около 2 месяцев назад

Heap-based Buffer Overflow in GNU coreutils

CVSS3: 6.1
debian
около 2 месяцев назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow d ...

rocky
11 дней назад

Moderate: coreutils security update

6.1 Medium

CVSS3