vulnti.work

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-…

Medium CVSS 6.1
CVECVE-2025-14104
First seen2026-08-21 14:16 UTC
Disclosed2025-12-05 17:16 UTC
Last updated2026-08-21 14:16 UTC
Channel statusauto

Summary

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD