CVE-2025-14104: Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

Overview

Severity
Medium (CVSS 6.1)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U
Exploit Status
Not Exploited
Patch Tuesday
2025-Dec
Released
2025-12-13
Last Updated
2026-01-08
EPSS Score
0.01% (percentile: 0.5%)

Affected Products (4)

Other

  • 20195-17086
  • 20786-17086
  • 20754-17084
  • 20804-17084

Revision History

  • 2025-12-13: Information published.
  • 2025-12-27: Information published.
  • 2025-12-30: Information published.
  • 2026-01-03: Information published.
  • 2026-01-08: Information published.