GHSA-ch64-4x3c-w3jqMediumCVSS 4.4

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap...

Published
May 27, 2025
Last Modified
May 19, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

🔗 References (11)