CVE-2025-14104
published 2025-12-05CVE-2025-14104: A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()`…
PriorityP428medium6.1CVSS 3.1
AVLACLPRLUINSUCLINAH
EPSS
0.18%
7.7th percentile
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.41.3-1 (forky) | util-linux 2.41.3-1 (forky) |
| kernel | util-linux | >= 0 < 2.41.3-1 | 2.41.3-1 |
| msrc | azl3_util-linux_2.40.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_util-linux_2.40.2-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_util-linux_2.37.4-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_util-linux_2.37.4-9_on_cbl_mariner_2.0 | — | — |
| util-linux | util-linux | < 2.41.3 | 2.41.3 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
vendor_msrc·2025-12-09·CVSS 6.1
CVE-2025-14104 [MEDIUM] CWE-125 Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames
vendor_redhat·2025-12-05·CVSS 6.1
CVE-2025-14104 [MEDIUM] CWE-125 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames
util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to wi
Debian
CVE-2025-14104: util-linux - A flaw was found in util-linux. This vulnerability allows a heap buffer overread...
vendor_debian·2025·CVSS 6.1
CVE-2025-14104 [MEDIUM] CVE-2025-14104: util-linux - A flaw was found in util-linux. This vulnerability allows a heap buffer overread...
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.41.3-1)
sid: resolved (fixed in 2.41.3-1)
trixie: open
OSV
CVE-2025-14104: A flaw was found in util-linux
osv·2025-12-05·CVSS 6.1
CVE-2025-14104 [MEDIUM] CVE-2025-14104: A flaw was found in util-linux
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
GHSA
GHSA-hrx4-rccm-xj6c: A flaw was found in util-linux
ghsa_unreviewed·2025-12-05
CVE-2025-14104 [MEDIUM] CWE-125 GHSA-hrx4-rccm-xj6c: A flaw was found in util-linux
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:1696https://access.redhat.com/errata/RHSA-2026:1852https://access.redhat.com/errata/RHSA-2026:1913https://access.redhat.com/errata/RHSA-2026:2485https://access.redhat.com/errata/RHSA-2026:2563https://access.redhat.com/errata/RHSA-2026:2737https://access.redhat.com/errata/RHSA-2026:2800https://access.redhat.com/errata/RHSA-2026:3406https://access.redhat.com/errata/RHSA-2026:4943https://access.redhat.com/errata/RHSA-2026:7180https://access.redhat.com/security/cve/CVE-2025-14104https://bugzilla.redhat.com/show_bug.cgi?id=2419369
2025-12-05
Published