The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based buffer overflow in the alloca function.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 11, 2015 |
| Oracle_linux | — | Upgrade coreutilsUpgrade coreutils-libs | Oct 16, 2024 | Nov 23, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 15, 2013 |
| Suse | — | Upgrade coreutils-debuginfoUpgrade coreutils-debuginfo-x86Upgrade coreutils-langUpgrade coreutils-x86Upgrade coreutilsUpgrade coreutils-testsuiteUpgrade coreutils-debugsource | Dec 12, 2013 | Nov 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub