We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.
Reserved 2025-05-27 | Published 2025-05-27 | Updated 2025-05-29 | Assigner redhat2025-05-27: | Reported to Red Hat. |
2025-05-27: | Made public. |
Red Hat would like to thank Mohamed Maatallah for reporting this issue.
access.redhat.com/security/cve/CVE-2025-5278
bugzilla.redhat.com/show_bug.cgi?id=2368764 (RHBZ#2368764)
Support options