Skip to content
VulniPulse
Advisory severityMedium4.4Red Hat Linux

Medium [CVE-2026-56392] GNU coreutils unexpand: Denial of Service via crafted tab stop values

This medium-severity Red Hat Linux advisory covers CVE-2026-56392 affecting Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 10.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-56392 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.

When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.

This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries.

Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation. A local attacker could exploit this by providing crafted input, causing the utility to crash and potentially leading to a denial of service or arbitrary memory manipulation.

Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L). Weakness: CWE-787.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Fixed versions
  • coreutils-0:8.30-20.el8_10
  • coreutils-main-9.11-5.hum1
  • RHBA-2026:47115
  • RHSA-2026:40724

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.