---
id: CVE-2025-5278
title: A flaw was found in GNU Coreutils
summary: >-
  A flaw was found in GNU Coreutils. The sort utility's begfield() function is
  vulnerable to a heap buffer under-read. The program may access memory outside
  the allocated buffer if a user runs a crafted command using the traditional
  key fo…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'
cwe:
  - CWE-121
vendor: Red Hat
product: coreutils
affected:
  - coreutils >= 7.2 < 9.8
  - coreutils (all versions)
  - coreutils (all versions)
  - costmanagement/costmanagement-metrics-rhel9-operator (all versions)
  - discovery/discovery-ui-rhel9 (all versions)
  - discovery/discovery-server-rhel9 (all versions)
  - insights-proxy/insights-proxy-container-rhel9 (all versions)
  - rhosdt/tempo-gateway-opa-rhel9 (all versions)
  - rhosdt/tempo-gateway-rhel9 (all versions)
  - rhosdt/tempo-jaeger-query-rhel9 (all versions)
  - rhosdt/tempo-operator-bundle (all versions)
  - rhosdt/tempo-query-rhel9 (all versions)
  - rhosdt/tempo-rhel9 (all versions)
  - rhosdt/tempo-rhel9-operator (all versions)
  - rhosdt/opentelemetry-collector-rhel9 (all versions)
  - rhosdt/opentelemetry-rhel9-operator (all versions)
  - rhui5/cds-kubernetes-rhel9 (all versions)
  - rhui5/cds-rhel9 (all versions)
  - rhui5/haproxy-rhel9 (all versions)
  - rhui5/installer-rhel9 (all versions)
  - rhui5/rhua-rhel9 (all versions)
  - rhui5/cds-kubernetes-tp-rhel9 (all versions)
  - rhui5/installer-tp-rhel9 (all versions)
  - rhui5/rhua-tp-rhel9 (all versions)
  - coreutils
  - coreutils
  - coreutils (all versions)
  - openshift/ose-rhel-coreos-8 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
patched:
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_9
  - cost_management 4
  - discovery 2
  - insights_proxy 1.5
  - openshift_distributed_tracing 3.10.2
  - update_infrastructure 5
published: '2025-05-27'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:17:36.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5278'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:28911'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:33124'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:33313'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:33612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:34102'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:39981'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:44481'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:46836'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:50205'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69964'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-5278'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2368764'
    label: secalert@redhat.com
  - url: >-
      https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
    label: secalert@redhat.com
  - url: 'https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2025/05/27/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/05/29/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/05/29/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security-tracker.debian.org/tracker/CVE-2025-5278'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-5278'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5278'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00288
epssPercentile: 0.19011
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-05-28T13:46:35.101788Z'
ingestedAt: '2026-06-29T13:24:34.348Z'
---

## Overview

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:33124** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:33124)
- **RHSA-2026:28911** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:28911)
- **RHSA-2026:39981** · Red Hat · fixed in: Cost Management 4 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39981)
- **RHSA-2026:46836** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46836)
- **RHSA-2026:33313** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:33313)
- **RHSA-2026:34102** · Red Hat · fixed in: Red Hat Insights proxy 1.5 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34102)
- **RHSA-2026:50205** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50205)
- **RHSA-2026:33612** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33612)
- **RHSA-2026:44481** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44481)
- **RHSA-2026:58981** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58981)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5278.json)
- **RHSA-2026:69964** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69964)
