{"id":"CVE-2025-5278","title":"A flaw was found in GNU Coreutils","summary":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key fo…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","cwe":["CWE-121"],"vendor":"Red Hat","product":"coreutils","affected":["coreutils >= 7.2 < 9.8","coreutils (all versions)","coreutils (all versions)","costmanagement/costmanagement-metrics-rhel9-operator (all versions)","discovery/discovery-ui-rhel9 (all versions)","discovery/discovery-server-rhel9 (all versions)","insights-proxy/insights-proxy-container-rhel9 (all versions)","rhosdt/tempo-gateway-opa-rhel9 (all versions)","rhosdt/tempo-gateway-rhel9 (all versions)","rhosdt/tempo-jaeger-query-rhel9 (all versions)","rhosdt/tempo-operator-bundle (all versions)","rhosdt/tempo-query-rhel9 (all versions)","rhosdt/tempo-rhel9 (all versions)","rhosdt/tempo-rhel9-operator (all versions)","rhosdt/opentelemetry-collector-rhel9 (all versions)","rhosdt/opentelemetry-rhel9-operator (all versions)","rhui5/cds-kubernetes-rhel9 (all versions)","rhui5/cds-rhel9 (all versions)","rhui5/haproxy-rhel9 (all versions)","rhui5/installer-rhel9 (all versions)","rhui5/rhua-rhel9 (all versions)","rhui5/cds-kubernetes-tp-rhel9 (all versions)","rhui5/installer-tp-rhel9 (all versions)","rhui5/rhua-tp-rhel9 (all versions)","coreutils","coreutils","coreutils (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"patched":["enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_9","cost_management 4","discovery 2","insights_proxy 1.5","openshift_distributed_tracing 3.10.2","update_infrastructure 5"],"published":"2025-05-27","updated":"2026-09-22","sourceUpdated":"2026-09-22T16:17:36.780","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:28911","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33124","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33313","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33612","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:34102","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:39981","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:44481","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:46836","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50205","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:58981","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69964","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-5278","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2368764","label":"secalert@redhat.com"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","label":"secalert@redhat.com"},{"url":"https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/27/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/29/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/29/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security-tracker.debian.org/tracker/CVE-2025-5278","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-5278"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00288,"epssPercentile":0.21676,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-05-28T13:46:35.101788Z"},"ingestedAt":"2026-06-29T13:24:34.348Z","slug":"CVE-2025-5278","body":"## Overview\n\nA flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:33124** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:33124)\n- **RHSA-2026:28911** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:28911)\n- **RHSA-2026:39981** · Red Hat · fixed in: Cost Management 4 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39981)\n- **RHSA-2026:46836** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46836)\n- **RHSA-2026:33313** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:33313)\n- **RHSA-2026:34102** · Red Hat · fixed in: Red Hat Insights proxy 1.5 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34102)\n- **RHSA-2026:50205** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50205)\n- **RHSA-2026:33612** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33612)\n- **RHSA-2026:44481** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44481)\n- **RHSA-2026:58981** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58981)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json)\n- **RHSA-2026:69964** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69964)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}