https://seclists.org/oss-sec/2025/q2/181: CVE-2025-5278: Heap Buffer Overflow in GNU Coutils sort
Published May 29, 2025
·Updated
Affected Software
1 affected component
GNU Coreutils
Frequently Asked Questions
1
What is the severity of CVE-2025-5278?
CVE-2025-5278 has a high severity due to its potential for remote exploitation via a heap buffer overflow.
2
How do I fix CVE-2025-5278?
To fix CVE-2025-5278, update to the latest version of GNU Coreutils that addresses this vulnerability.
3
What systems are affected by CVE-2025-5278?
CVE-2025-5278 affects systems using GNU Coreutils when handling specific key specifications in traditional format.
4
Is CVE-2025-5278 exploitable?
Yes, CVE-2025-5278 is exploitable when a user passes certain key specifications to the sort command.
5
What are the consequences of CVE-2025-5278?
The consequences of CVE-2025-5278 include potential arbitrary code execution or application crashes due to the heap buffer overflow.