CVE-2025-14104: Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
Overview
- Severity
- Medium (CVSS 6.1)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2025-Dec
- Released
- 2025-12-13
- Last Updated
- 2026-01-08
- EPSS Score
- 0.01% (percentile: 0.5%)
Affected Products (4)
Other
- 20195-17086
- 20786-17086
- 20754-17084
- 20804-17084
Revision History
- 2025-12-13: Information published.
- 2025-12-27: Information published.
- 2025-12-30: Information published.
- 2026-01-03: Information published.
- 2026-01-08: Information published.