Untriaged
Permalink
CVE-2025-14104
6.1 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): HIGH
by @jopejoe1 Activity log
- Created automatic suggestion
- @jopejoe1 removed package uutils-util-linux
Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
References
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1852 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1913 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1852 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1913 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2485 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1852 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1913 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2485 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2563 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1852 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1913 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2485 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2563 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2737 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
- RHSA-2026:1696 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1852 x_refsource_REDHAT vendor-advisory
- RHSA-2026:1913 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2485 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2563 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2737 x_refsource_REDHAT vendor-advisory
- RHSA-2026:2800 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-14104 x_refsource_REDHAT vdb-entry
- RHBZ#2419369 issue-tracking x_refsource_REDHAT
Affected products
rhcos
util-linux
- *
- <2.41.3
util-linux-ng
rhceph/rhceph-7-rhel9
- *
rhceph/rhceph-8-rhel9
- *
rhui5/installer-rhel9
- *
insights-proxy/insights-proxy-container-rhel9
- *
Matching in nixpkgs
pkgs.more
None
pkgs.wall
None
pkgs.eject
None
pkgs.mount
None
pkgs.logger
None
pkgs.hexdump
None
pkgs.libuuid
Set of system utilities for Linux
pkgs.utillinux
Set of system utilities for Linux
pkgs.util-linux
Set of system utilities for Linux
pkgs.libsmartcols
Set of system utilities for Linux
pkgs.unixtools.col
None
pkgs.unixtools.fsck
None
pkgs.unixtools.more
None
pkgs.unixtools.wall
None
pkgs.unixtools.eject
None
pkgs.unixtools.fdisk
None
pkgs.unixtools.mount
None
pkgs.unixtools.write
None
pkgs.unixtools.column
None
pkgs.unixtools.getopt
None
pkgs.unixtools.logger
None
pkgs.unixtools.script
None
pkgs.unixtools.umount
None
pkgs.unixtools.hexdump
None
pkgs.unixtools.whereis
None
pkgs.util-linuxMinimal
Set of system utilities for Linux
pkgs.unixtools.util-linux
None
-
nixos-unstable 1003.1-2008
- nixpkgs-unstable 1003.1-2008
- nixos-unstable-small 1003.1-2008
-
nixos-25.11 -
- nixos-25.11-small 1003.1-2008
- nixpkgs-25.11-darwin 1003.1-2008
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>