Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14104

6.1MEDIUM

What is CVE-2025-14104?

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-14104 : Heap Buffer Overread Vulnerability in util-linux by Red Hat