🔐 CVE Alert

CVE-2026-56391

UNKNOWN 0.0

Out‑of‑bounds Read in GNU coreutils

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

CWE CWE-125
Vendor gnu
Product coreutils
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for gnu coreutils

Be the first to know when new unknown vulnerabilities affecting gnu coreutils are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

GNU / coreutils
9.5 ≤ 9.11

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/07/CVE-2026-56391 git.savannah.gnu.org: https://git.savannah.gnu.org/cgit/coreutils.git/ git.savannah.gnu.org: https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371

Credits

Michał Majchrowicz (AFINE Team) Marcin Wyczechowski (AFINE Team)