Name
CVE-2025-14104
Description
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
Analysis#
Vulnerability Ratings#
6.1
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
util-linux (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Update setpwnam.c
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104
2
Update bufflen
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104
util-linux (yocto:kirkstone)
#
Title
Author
Resolve
1
Update setpwnam.c
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104
2
Update bufflen
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104
util-linux (yocto:scarthgap)
#
Title
Author
Resolve
1
Update setpwnam.c
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104
2
Update bufflen
Mohamed Maatallah <hotelsmaatallahrecemail@gmail.com>
CVE-2025-14104