RHSA-2026:33124: Moderate: coreutils security update
Moderate: coreutils security update
Other sources
The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages.Security Fix(es): coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification (CVE-2025-5278) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/coreutilsto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutils-commonto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutils-debuginfoto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutils-debugsourceto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutils-singleto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutils-single-debuginfoto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2 - Upgrade
Upgrade
redhat/coreutilsto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Upgrade
Upgrade
redhat/coreutils-commonto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Upgrade
Upgrade
redhat/coreutils-debuginfoto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Upgrade
Upgrade
redhat/coreutils-debugsourceto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Upgrade
Upgrade
redhat/coreutils-singleto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Upgrade
Upgrade
redhat/coreutils-single-debuginfoto a version that resolves this vulnerability.Fixed in 9.5-8.el10_2.aa - Compensating control
Check whether your environment includes the vulnerable GNU Coreutils sort code path that uses key specification; prioritize limiting exposure of systems that accept untrusted input to coreutils sort until the coreutils security update is applied (issue described: CVE-2025-5278).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:33124?
The severity of RHSA-2026:33124 is classified as medium with a score of 4.
What vulnerability is addressed in RHSA-2026:33124?
RHSA-2026:33124 addresses a Heap Buffer Under-Read vulnerability in GNU Coreutils sort via Key Specification identified as CVE-2025-5278.
How do I fix RHSA-2026:33124?
To fix RHSA-2026:33124, update the coreutils package to the latest version provided by Red Hat.
Which packages are affected by RHSA-2026:33124?
The affected packages include redhat/coreutils, redhat/coreutils-common, redhat/coreutils-debuginfo, and several others related to GNU Core Utilities.
Is RHSA-2026:33124 relevant for all Red Hat systems?
RHSA-2026:33124 is relevant for Red Hat Enterprise Linux systems, including both ARM 64 and x86_64 architectures.