CVE-2025-5278

ADVISORY - debian

Summary

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.


EPSS Score: 0.00015 (0.020)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Stack-based Buffer Overflow

ADVISORY - redhat

Stack-based Buffer Overflow


Debian

CREATED

UPDATED

ADVISORY IDCVE-2025-5278
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/coreutilsdebdebian12>=9.1-1Not yet available
debian/coreutilsdebdebianunstable>=9.7-3Not yet available
debian/coreutilsdebdebian11>=8.32-4Not yet available
debian/coreutilsdebdebian13>=9.7-3Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2025-5278
EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

4.4medium

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2025-5278
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2025-5278
EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

4.4medium

Photon

CREATED

UPDATED

ADVISORY ID

CVE-2025-5278

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

4.4medium