CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56391

unknowncovered by 1 sourcefirst seen 2026-07-24
GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

⚡ Watch CVE-2026-56391

Get an email if CVE-2026-56391 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-56391

CVE.org record

Embed the live status

CVE-2026-56391 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56391 status](https://www.csirts.com/badge/CVE-2026-56391)](https://www.csirts.com/cve/CVE-2026-56391)