#VU109921 Out-of-bounds read in coreutils - CVE-2025-5278
Published: May 29, 2025
coreutils
GNU
Description
The vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the begfield() function when handling an overly large key value. A remote attacker can trick the victim into passing specially crafted input to the application, trigger an out-of-bounds read error and read contents of memory on the system.