PT-2026-64260 · Gnu · Coreutils

·

CVE-2026-56392

·

Published

2026-07-24

·

Updated

2026-09-10

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions GNU coreutils (affected versions not specified)
Description The unexpand utility is susceptible to a heap-based buffer overflow caused by an integer overflow during buffer allocation. This occurs when the software processes large values provided via the -t tab stop argument, causing the multiplication used for allocation size to wrap around and create an undersized buffer. Consequently, processing crafted input leads to an out-of-bounds heap write, which can result in a crash or potentially allow a heap write primitive depending on the memory layout.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:66403
CVE-2026-56392
ECHO-F08C-7E47-8652
JLSEC-2026-1196
OESA-2026-3388
OESA-2026-3389
OESA-2026-3390
OESA-2026-3391
OESA-2026-3416
RHSA-2026:40724

Affected Products

Coreutils