rpm package
almalinux/coreutils-single
pkg:rpm/almalinux/coreutils-single
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56392 | Low | — | < 8.32-41.el9_8.1 | 8.32-41.el9_8.1 | Jul 24, 2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When p | |
| CVE-2026-56391 | Med | — | < 9.5-8.el10_2.1 | 9.5-8.el10_2.1 | Jul 24, 2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing t | |
| CVE-2025-5278 | Med | 4.4 | < 8.32-41.el9_8 | 8.32-41.el9_8 | May 27, 2025 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a cra |
- affected < 8.32-41.el9_8.1fixed 8.32-41.el9_8.1
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When p
- affected < 9.5-8.el10_2.1fixed 9.5-8.el10_2.1
GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing t
- affected < 8.32-41.el9_8fixed 8.32-41.el9_8
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a cra