Description
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
Problem types
Product status
Any version before 2.41.3
0:2.40.2-15.el10_1 (rpm) before *
0:2.32.1-48.el8_10 (rpm) before *
0:2.32.1-48.el8_10 (rpm) before *
Timeline
| 2025-12-05: | Reported to Red Hat. |
| 2025-12-05: | Made public. |
References
access.redhat.com/errata/RHSA-2026:1696 (RHSA-2026:1696)
access.redhat.com/errata/RHSA-2026:1852 (RHSA-2026:1852)
access.redhat.com/security/cve/CVE-2025-14104
bugzilla.redhat.com/show_bug.cgi?id=2419369 (RHBZ#2419369)