CVE-2025-5278 - log back

CVE-2025-5278 created at 27 May 2025 23:23:46
Severity
+ Medium
Remote
+ Local
Type
+ Information disclosure
Description
+ A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.
References
+ https://lists.gnu.org/archive/html/bug-coreutils/2025-05/msg00036.html
+ https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507
+ https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
+ https://github.com/advisories/GHSA-ch64-4x3c-w3jq
Notes