Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14104
6.1MEDIUM
What is CVE-2025-14104?
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.