Heap Buffer Overread Vulnerability in util-linux by Red Hat
CVE-2025-14104

6.1MEDIUM

What is CVE-2025-14104?

A vulnerability exists in the util-linux package, specifically within the setpwnam() function. This flaw allows for a heap buffer overread when processing usernames that are 256 bytes long. It affects the SUID (Set User ID) login-utils utilities that interact with the password database, potentially exposing sensitive information and posing a risk to system integrity.

Affected Version(s)

Red Hat Ceph Storage 7 sha256:485411749726179fe5cd880e2cf308261b35150e4b356ddb7100f52e02b2e353

Red Hat Ceph Storage 8 sha256:2325f237ab329cb3f1d3db4da40ed19f68d6daa2a5902c71be3f0d3cfcadd503

Red Hat Ceph Storage 9 sha256:53a72419a7e4f4b332b9c6759ff1c389f226e26599236bc770d367c68bba911a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.