Critical Vulnerabilities in GNU Core Utilities Affecting Ubuntu 26.04

Critical Vulnerabilities in GNU Core Utilities Affecting Ubuntu 26.04

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were identified in GNU Core Utilities affecting Ubuntu 26.04 LTS. CVE-2025-5278 involves a heap buffer under-read in the sort command, potentially leading to denial of service or information leakage. CVE-2026-56391 concerns an out-of-bounds read in the uniq command when using crafted multibyte input, also allowing for denial of service or sensitive data exposure. Both vulnerabilities can be exploited by local attackers. Users are advised to update their systems to mitigate these risks. The issues were disclosed in security notices published on August 31, 2026. Affected systems should prioritize applying the necessary updates to ensure security.

Key Points: • Two critical vulnerabilities in GNU Core Utilities affect Ubuntu 26.04 LTS. • CVE-2025-5278 and CVE-2026-56391 can lead to denial of service or information leakage. • Local attackers can exploit these vulnerabilities, necessitating immediate updates.

Timeline

2025-05-27
CVE-2025-5278 published
Heap buffer under-read in GNU Core Utilities sort function discovered, affecting Ubuntu 26.04 LTS.
Ubuntu
2026-07-24
CVE-2026-56391 published
Out-of-bounds read vulnerability in GNU Core Utilities uniq command identified, affecting Ubuntu 26.04 LTS.
Linuxsecurity
2026-08-31
Security notice published
Ubuntu released USN-8697-1 advising users to update GNU Core Utilities to mitigate vulnerabilities.
Ubuntu