{"id":"CVE-2025-14104","title":"A flaw was found in util-linux","summary":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the passwor…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","cwe":["CWE-125"],"published":"2025-12-05","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:1696","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:1852","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:1913","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2485","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2563","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2737","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2800","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:3406","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:4943","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:7180","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-14104","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2419369","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00193,"epssPercentile":0.07971,"ingestedAt":"2026-06-29T13:24:34.616Z","slug":"CVE-2025-14104","body":"## Overview\n\nA flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}