{"id":"AZL-93060","summary":"CVE-2025-5278 affecting package coreutils for versions less than 9.4-7","details":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.","modified":"2026-08-31T05:26:27Z","published":"2025-05-27T21:15:23Z","upstream":["CVE-2025-5278"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278"}],"affected":[{"package":{"name":"coreutils","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/coreutils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4-7"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93060.json"}}],"schema_version":"1.9.0"}