CVE-2026-56391
Received Received - Intake

Out-of-Bounds Read in GNU Coreutils uniq

Vulnerability report for CVE-2026-56391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: CERT.PL

Description

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnu coreutils From 8.32 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GNU coreutils uniq has an out-of-bounds read vulnerability when processing multibyte input with the -w option. The find_field() function incorrectly calculates character byte length by not advancing through input, leading to an inflated length value. This causes memcmp to read beyond buffer limits when handling crafted input, potentially crashing the program and exposing adjacent heap memory.

Detection Guidance

To detect this vulnerability, check if GNU coreutils uniq is installed and verify its version. If the version is older than the fixed commit d64e35a8a4c0e4608321433e0d84d917e4e36371, it may be vulnerable. Run uniq with the -w option and crafted multibyte input to test for crashes or memory exposure.

Impact Analysis

This vulnerability could allow an attacker to crash the uniq program or read sensitive memory contents if they provide specially crafted multibyte input. Since uniq is commonly used in scripts and data processing pipelines, this could disrupt operations or expose confidential information in memory.

Mitigation Strategies

Update GNU coreutils to a version that includes the fix in commit d64e35a8a4c0e4608321433e0d84d917e4e36371. Avoid using the -w option with uniq until patched. Monitor for crashes or unusual memory behavior when processing multibyte input.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart