CVE-2026-56392
published 2026-07-24CVE-2026-56392: GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t)…
PriorityP418low1.8CVSS 4.0
AVLACLATPPRNUIAVCNVILVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.15%
4.5th percentile
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.
This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | coreutils | <= 9.11 | — |
| uutils | coreutils | — | — |
CVSS provenance
nvdv4.01.8LOWCVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values.
ghsa_unreviewed·2026-07-24
CVE-2026-56392 [LOW] CWE-122 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values.
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.
This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d
Red Hat
coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
vendor_redhat·2026-07-24·CVSS 1.8
CVE-2026-56392 [LOW] CWE-787 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.
Statement: A Moderate impact heap-based buffer overflow flaw was found in the `unexpand` utility of GNU coreutils. This vulnerability arises from an integer overflow when processing unusually large tab stop v
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values [fedora-all]
bugzilla·2026-07-24·CVSS 1.8
CVE-2026-56392 [LOW] CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values [fedora-all]
CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab sto
Bugzilla
CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
bugzilla·2026-07-24·CVSS 1.8
CVE-2026-56392 [LOW] CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVE-2026-56392 coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.
This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d
2026-07-24
Published