Heap Buffer Overread Vulnerability in util-linux by Red Hat
CVE-2025-14104
6.1MEDIUM
Key Information:
- Vendor
Util-linux
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-14104?
A vulnerability exists in the util-linux package, specifically within the setpwnam() function. This flaw allows for a heap buffer overread when processing usernames that are 256 bytes long. It affects the SUID (Set User ID) login-utils utilities that interact with the password database, potentially exposing sensitive information and posing a risk to system integrity.
Affected Version(s)
Red Hat Ceph Storage 7 sha256:485411749726179fe5cd880e2cf308261b35150e4b356ddb7100f52e02b2e353
Red Hat Ceph Storage 8 sha256:2325f237ab329cb3f1d3db4da40ed19f68d6daa2a5902c71be3f0d3cfcadd503
Red Hat Ceph Storage 9 sha256:53a72419a7e4f4b332b9c6759ff1c389f226e26599236bc770d367c68bba911a
