#VU119955 Heap-based buffer overflow in Util-linux - CVE-2025-14104
Published: December 15, 2025 / Updated: April 1, 2026
Util-linux
kernel.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing 256-byte usernames within the setpwnam() function. A local user can trigger a heap-based buffer overflow and execute arbitrary code on the target system.
The vulnerability affects any SUID login-utils utility writing to password database.