CVE-2025-5278
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access
CVSS
4.4
Medio
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Publicado: 27 may 2025 · Última mod.: 1 sept 2026 · CWE-121
0.2%EPSS · 30 días0.3%
2026-08-042026-08-31
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28911
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33124
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33313
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33612
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34102
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:39981
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:44481
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:46836
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:50205
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:58981
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-5278
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2368764
- cgit.git.savannah.gnu.orghttps://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
- debbugs.gnu.orghttps://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2025/05/27/2
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2025/05/29/1
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2025/05/29/2
- cgit.git.savannah.gnu.orghttps://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
- cgit.git.savannah.gnu.orghttps://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14
- security-tracker.debian.orghttps://security-tracker.debian.org/tracker/CVE-2025-5278
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-826169.9 CRÍ46.9%
——14A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.2dCVE-2026-825939.9 CRÍ41.5%
——12A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.2dCVE-2026-825929.9 CRÍ53.0%
——16A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.1dCVE-2026-824787.3 ALT25.6%
——8A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.3dCVE-2026-772184.9 MED34.2%
——10PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the web_sys_enablePasswd_post handler copies the enbPass POST parameter into a fixed-size stack buffer without length validation, and the web_sys_localUser_post handler copies the usrName and usrPass POST parameters into fixed-size stack buffers without length validation. A remote authenticated attacker can send a crafted request to crash the CGI process or web management service, resulting in denial of service.4dCVE-2026-772174.9 MED36.1%
——11PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radKey_0, radDftParamKey, radName, and radIp POST parameters into fixed-size stack buffers without length validation, and additionally dereferences radName and radIp without verifying their presence in the request. A remote authenticated attacker can send crafted requests to crash the CGI process or web management service, resulting in denial of service.1d