HackTesting
HomeArticlesTagsContact

CVE-2025-14104

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

References

https://access.redhat.com/errata/RHSA-2026:1696
https://access.redhat.com/errata/RHSA-2026:1852
https://access.redhat.com/errata/RHSA-2026:1913
https://access.redhat.com/errata/RHSA-2026:2485
https://access.redhat.com/errata/RHSA-2026:2563
https://access.redhat.com/errata/RHSA-2026:2737
https://access.redhat.com/errata/RHSA-2026:2800
https://access.redhat.com/errata/RHSA-2026:3406
https://access.redhat.com/errata/RHSA-2026:4943
https://access.redhat.com/errata/RHSA-2026:7180
https://access.redhat.com/security/cve/CVE-2025-14104
https://bugzilla.redhat.com/show_bug.cgi?id=2419369
Published
Dec 5, 2025 16:22:09 UTC
Updated
Apr 19, 2026 19:37:37 UTC
Reserved
Dec 5, 2025 14:18:15 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.