A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | util-linux-0:2.40.2-15.el10_1 | * |
| Red Hat Enterprise Linux 8 | RedHat | util-linux-0:2.32.1-48.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | util-linux-0:2.32.1-48.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | util-linux-0:2.37.4-21.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | util-linux-0:2.37.4-21.el9_7 | * |
| Red Hat Ceph Storage 7 | RedHat | rhceph/rhceph-7-rhel9:sha256:df2032db9a082aa0d08adfc76a18d65548d2c2f14dedad0dc35bc0117aca42b8 | * |
| Red Hat Ceph Storage 8 | RedHat | rhceph/rhceph-8-rhel9:sha256:ecd314ed5a994812d976dbccf0d3c4db54fadf5c1cba46d1fa0b2f0a1fd0e921 | * |
| Red Hat Ceph Storage 9 | RedHat | rhceph/rhceph-9-rhel9:sha256:8c65a91917296ce25845bd673c521448c89140a126216bf939355b40d38770db | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:sha256:ab86ba36e62e8aec5ba48e9e0076b1f8086c48157c85990be0e2ce3e03273016 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:sha256:d98fd3fe5f5f9acd0efae7db19b61b864be1eb2fbe2586a1b6be2429fa2cc7a3 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:sha256:5f1fbf66fb349a7baf066a1216d39989c3b89f18ec5108b96d9643baf4856778 | * |
| Util-linux | Ubuntu | upstream | * |