PoC Index

CVE-2025-5278

MEDIUM 4.4EPSS 0.3%

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS v3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
EPSS
0.27% chance of exploitation in the next 30 days, 18th percentile
Published
2025-05-27
Updated
2026-08-31

Proof-of-concept exploits (1)

References

Related