A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | util-linux-0:2.40.2-15.el10_1 | * |
| Red Hat Enterprise Linux 8 | RedHat | util-linux-0:2.32.1-48.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | util-linux-0:2.32.1-48.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | util-linux-0:2.37.4-21.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | util-linux-0:2.37.4-21.el9_7 | * |
| Red Hat Ceph Storage 7 | RedHat | rhceph/rhceph-7-rhel9:1770632724 | * |
| Red Hat Ceph Storage 8 | RedHat | rhceph/rhceph-8-rhel9:1770630907 | * |
| Red Hat Ceph Storage 9 | RedHat | rhceph/rhceph-9-rhel9:1771816028 | * |
| Red Hat Hardened Images | RedHat | util-linux-main-2.42-7.1.hum1 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:1770740405 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1770646925 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1773670073 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1773672059 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1773670137 | * |
| Util-linux | Ubuntu | esm-infra/xenial | * |
| Util-linux | Ubuntu | upstream | * |