Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93060.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93060
Upstream
Published
2025-05-27T21:15:23Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2025-5278 affecting package coreutils for versions less than 9.4-7
Details

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

References

Affected packages

Azure Linux:3 / coreutils

Package

Name
coreutils
Purl
pkg:rpm/azure-linux/coreutils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93060.json"