coreutils-8.30-21.el8_10

エラータID: AXSA:2026-1940:06

Release date: 
Wednesday, September 30, 2026 - 15:21
Subject: 
coreutils-8.30-21.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages.

Security Fix(es):

* coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification (CVE-2025-5278)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-5278
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. coreutils-8.30-21.el8_10.src.rpm
    MD5: bd3be7742c75e8c214f62202cebc6d2f
    SHA-256: 13a59e07074613ab317c73955389da6ae29ddbf296649b378b057c3cf00da7c6
    Size: 5.30 MB

Asianux Server 8 for x86_64
  1. coreutils-8.30-21.el8_10.x86_64.rpm
    MD5: 5fa8a775b65a7b50305e522c33a23437
    SHA-256: 204ccc4859c7132e33da99bcb76bcf5af04a9247d97d6b5a6122f9d743442359
    Size: 1.21 MB
  2. coreutils-common-8.30-21.el8_10.x86_64.rpm
    MD5: b8bfb4ed443697f2c4134ac0cbf7976b
    SHA-256: 6697081b3b3c9f27655c5058e60da6a8c8fd1871501b58a6074de0ccdd259899
    Size: 2.00 MB
  3. coreutils-single-8.30-21.el8_10.x86_64.rpm
    MD5: 60d93d8deb4d5634a695379e0615249d
    SHA-256: a1e1548fa86b3cac38e17f98768d3f6e94a34eec60ad4a9b949319eed88e200b
    Size: 629.21 kB