REDHAT-BUG-2419369: Medium severity util-linux util-linux vulnerability
A flaw was found in util-linux. Heap buffer overread when processing 256-byte usernames. Affects any SUID login-utils utility writing to password database. The setpwnam() function allocates a 256-byte buffer but accesses linebuf[256] when username length equals 256, causing a heap buffer overread.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2419369?
The severity of REDHAT-BUG-2419369 is considered high due to the potential for heap buffer overread vulnerabilities.
How do I fix REDHAT-BUG-2419369?
To fix REDHAT-BUG-2419369, update the util-linux package to the latest version that addresses this vulnerability.
What versions of util-linux are affected by REDHAT-BUG-2419369?
REDHAT-BUG-2419369 affects any version of util-linux that includes the flawed setpwnam() function.
Can REDHAT-BUG-2419369 be exploited remotely?
REDHAT-BUG-2419369 is likely to be exploitable locally since it involves SUID login-utils utilities.
What systems are at risk for REDHAT-BUG-2419369?
Systems running affected versions of util-linux that utilize SUID login-utils are at risk for REDHAT-BUG-2419369.